216.73.217.22

CVE-2026-27610

· Published 25/02/2026 03:16 · Modified 25/02/2026 14:15

Labels: CVE-2026-27610 2026-02-25CVE-2026-27610CWE-1289[email protected]

Essential information

Published
25/02/2026 03:16
Modified
25/02/2026 14:15
Author
Creator
CVSS
7.0 HIGH (v3) 7.0 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both master key and read-only master key when resolving function-typed keys. Under specific timing conditions, a read-only user can receive the cached full master key, or a regular user can receive the cached read-only master key. The fix in version 9.0.0-alpha.8 uses distinct cache keys for master key and read-only master key. As a workaround, avoid using function-typed master keys, or remove the `agent` configuration block from your dashboard configuration.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
parse / parse dashboard cpe:2.3:a:parse:parse_dashboard:7.3.0-alpha.42-9.0.0-alpha.7:*:*:*:*:*:*:*
parse / parse dashboard cpe:2.3:a:parse:parse_dashboard:9.0.0-alpha.8:*:*:*:*:*:*:*

References