CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-21892: parsl before 2026.01.05 (exclusive), < 2026.01.05

CVE-2026-21892. CVSS 3.1 base score 7.3 (HIGH, NVD). EPSS 0.00275 (percentile 0.18143), scored 2026-10-05.

Affected technology

parsl · before 2026.01.05 (exclusive)
uchicago

parsl · < 2026.01.05
Parsl

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An unauthenticated attacker with access to the visualization dashboard can inject arbitrary SQL commands, potentially leading to data exfiltration or denial of service against the monitoring database. Vendor/CNA’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low. NVD’s CVSS 3.1 assessment (base score 7.3/10) rates confidentiality, integrity and availability impact as low.

Published

CWE
CWE-89
CCR priority
29.3 /100 (P4)
CVSS 3.1
7.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L · NVD
EPSS
0.00275 · percentile 0.18143 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-21892.html