Authorization Bypass in Dify Product by Langgenius
CVE-2026-41947
Key Information:
- Vendor
Langgenius
- Status
- Vendor
- CVE Published:
- 18 May 2026
Badges
What is CVE-2026-41947?
The Dify application, specifically versions up to 1.14.1, is susceptible to an authorization bypass flaw. This issue enables authenticated users with editor privileges to manipulate trace configurations for any application, ignoring tenant ownership restrictions. Attackers can exploit this weakness to funnel messages and responses from targeted applications to LLM trace providers under their control. The ease of unauthenticated self-registration in Dify Cloud further heightens the risk, as it allows potential attackers to create accounts without verification.
Affected Version(s)
dify 0 <= 1.14.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
