CVE-2026-27595

🔴 HIGH

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security...

Published
Feb 25, 2026
Last Modified
Feb 27, 2026
Views
4
Bookmarks
0

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, allow unauthenticated remote attackers to perform arbitrary read and write operations against any connected Parse Server database using the master key. The agent feature is opt-in; dashboards without an agent config are not affected. The fix in version 9.0.0-alpha.8 adds authentication, CSRF validation, and per-app authorization middleware to the agent endpoint. Read-only users are restricted to the `readOnlyMasterKey` with write permissions stripped server-side. A cache key collision between master key and read-only master key was also corrected. As a workaround, remove or comment out the agent configuration block from your Parse Dashboard configuration.

Affected Products (135)

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.3.0

parseplatform - parse_dashboard

Version: 7.4.0

parseplatform - parse_dashboard

Version: 7.4.0

parseplatform - parse_dashboard

Version: 7.4.0

parseplatform - parse_dashboard

Version: 7.4.0

parseplatform - parse_dashboard

Version: 7.4.0

parseplatform - parse_dashboard

Version: 7.5.0

parseplatform - parse_dashboard

Version: 7.5.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 7.6.0

parseplatform - parse_dashboard

Version: 8.0.0

parseplatform - parse_dashboard

Version: 8.0.0

parseplatform - parse_dashboard

Version: 8.0.0

parseplatform - parse_dashboard

Version: 8.0.0

parseplatform - parse_dashboard

Version: 8.0.0

parseplatform - parse_dashboard

Version: 8.0.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.0

parseplatform - parse_dashboard

Version: 8.1.1

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.2.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.3.0

parseplatform - parse_dashboard

Version: 8.4.0

parseplatform - parse_dashboard

Version: 8.4.1

parseplatform - parse_dashboard

Version: 8.4.1

parseplatform - parse_dashboard

Version: 8.5.0

parseplatform - parse_dashboard

Version: 8.5.0

parseplatform - parse_dashboard

Version: 8.5.0

parseplatform - parse_dashboard

Version: 8.5.0

parseplatform - parse_dashboard

Version: 8.5.0

parseplatform - parse_dashboard

Version: 8.5.0

parseplatform - parse_dashboard

Version: 8.5.0

parseplatform - parse_dashboard

Version: 9.0.0

parseplatform - parse_dashboard

Version: 9.0.0

parseplatform - parse_dashboard

Version: 9.0.0

parseplatform - parse_dashboard

Version: 9.0.0

parseplatform - parse_dashboard

Version: 9.0.0

parseplatform - parse_dashboard

Version: 9.0.0

parseplatform - parse_dashboard

Version: 9.0.0

CVSS Scores

CVSS 3.1 7.5
7.5
HIGH
CVSS 2.0 7.5

Additional Information

Source
security-advisories@github.com
State
Analyzed

Share CVE-2026-27595

Share on Social Media

Copy Link

Embed Code

Request Expert Analysis

Request a professional security analysis for CVE-2026-27595 from our verified experts.

Credits System

Use your credits to get expert analysis from verified security professionals. Purchase more credits anytime!

Add 3 credits for accelerated delivery

Base Cost: 8 credits
Priority Upgrade: + credits
SLA Acceleration: +3 credits
Total Cost:
Your Balance:

Insufficient Credits

You need more credits to submit this request.

Buy Credits

Report Analysis