The AI Agent API endpoint (POST /apps/:appId/agent) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint by changing the app ID in the URL. Read-only users are given the full master key instead of the read-only master key and can supply write permissions in the request body to perform write and delete operations.
Affected are only dashboards with agent configuration enabled.
The fix adds per-app authorization checks and restricts read-only users to the readOnlyMasterKey with write permissions stripped server-side.
Remove the agent configuration block from your dashboard configuration. Dashboards without an agent config are not affected.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-25T18:59:44Z",
"nvd_published_at": "2026-02-25T03:16:04Z",
"severity": "CRITICAL"
}