Vulnerability Details CVE-2026-27608
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint by changing the app ID in the URL. Read-only users are given the full master key instead of the read-only master key and can supply write permissions in the request body to perform write and delete operations. Only dashboards with `agent` configuration enabled are affected. The fix in version 9.0.0-alpha.8 adds per-app authorization checks and restricts read-only users to the `readOnlyMasterKey` with write permissions stripped server-side. As a workaround, remove the `agent` configuration block from your dashboard configuration. Dashboards without an `agent` config are not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.3%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-27608
-
cpe:2.3:a:parseplatform:parse_dashboard:7.3.0
-
cpe:2.3:a:parseplatform:parse_dashboard:7.4.0
-
cpe:2.3:a:parseplatform:parse_dashboard:7.5.0
-
cpe:2.3:a:parseplatform:parse_dashboard:7.6.0
-
cpe:2.3:a:parseplatform:parse_dashboard:8.0.0
-
cpe:2.3:a:parseplatform:parse_dashboard:8.1.0
-
cpe:2.3:a:parseplatform:parse_dashboard:8.1.1
-
cpe:2.3:a:parseplatform:parse_dashboard:8.2.0
-
cpe:2.3:a:parseplatform:parse_dashboard:8.3.0
-
cpe:2.3:a:parseplatform:parse_dashboard:8.4.0
-
cpe:2.3:a:parseplatform:parse_dashboard:8.4.1
-
cpe:2.3:a:parseplatform:parse_dashboard:8.5.0
-
cpe:2.3:a:parseplatform:parse_dashboard:9.0.0