CVE-2026-27595: Parse Dashboard Unauthenticated Agent Endpoint

The Parse Dashboard AI Agent endpoint (`/apps/:appId/agent`) is exposed without authentication or CSRF protection. This allows unauthenticated remote attackers to perform arbitrary database operations using the master key.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-27595-parse-dashboard-unauthenticated-agent-endpoint --engine opengrep

Description

The Parse Dashboard AI Agent endpoint (`/apps/:appId/agent`) is exposed without authentication or CSRF protection. This allows unauthenticated remote attackers to perform arbitrary database operations using the master key.