CVE-2026-41947Disclosure(dify / dify)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dify dify systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to redirect all messages and responses from victim applications to attacker-controlled LLM trace providers. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dify

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • Peaked 5d ago at 2 mentions (2026-05-18); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
dify

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-05-18: 2Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Mentions · 2026-06-23: 2Mentions · 2026-07-02: 1Mentions · 2026-07-06: 1Patch / Workaround · 2026-06-23: 2Technical Details · 2026-05-18: 2Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-23: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-06: 105-1805-2005-2106-2307-0207-06
Signal classification2 categories
Disclosure
787.5%
Patch
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-182
Disclosure2
2026-05-201
Disclosure1
2026-05-211
Disclosure1
2026-06-232
Disclosure1Patch1
2026-07-021
Disclosure1
2026-07-061
Disclosure1
Full discourse8 posts
  • connect24h@connect24h
    Disclosure

    いやーん。これ影響範囲やばい。Dify公開していないからよかったけど、セルフホストで公開している場合は要対応。DifyでDifyTap、CVE-2026-41947〜41950の4件により他テナントのAIチャットや添付ファイルを読める恐れが出た。41947はCVSS 9.1、41948は9.4で、v1.14.2でも41948は次版待ち。公開アプリ、trace設定、Plugin Daemon経路、file_id参照ログを今すぐ洗ってほしい。これはSaaS型AI基盤の境界検証を甘く見ると終わる。 #セキュリティ https://is.gd/eKZ7qL

    Post summary

    The post announces four CVE‑2026‑41947 to 41950 vulnerabilities affecting the Dify platform, notes their high severity (CVSS 9.1‑9.4), and calls for immediate mitigation while awaiting vendor patches.

    012129216.3K
    5.9K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Difyでテナント跨ぎでデータが漏洩する脆弱性群DifyTapについて。CVE-2024-5846、CVE-2026-41947、CVE-2026-41948、CVE-2026-41949、CVE-2026-41950。CVE-2026-41948は未修正。それ以外はバージョン1.14.2で修正。 https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html?m=1

    Post summary

    The post identifies a group of DifyTap vulnerabilities (CVE‑2024‑5846, CVE‑2026‑41947‑41950), notes that CVE‑2026‑41948 remains unpatched, while the remaining issues are fixed in version 1.14.2.

    00020898
    7.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple Dify Vulnerabilities (CVE-2026-41947, CVE-2026-41948) Dify <= 1.14.1 is affected by critical authorization bypass and path traversal vulnerabilities that could allow authenticated attackers to access internal plugin daemon endpoints and redirect application traces from victim tenants to attacker-controlled providers. The issues impact multi-tenant isolation and may expose sensitive application prompts, messages, and responses across tenant boundaries. 👉 Affected: Dify <= 1.14.1

    Post summary

    The post announces two critical CVEs (CVE-2026-41947, CVE-2026-41948) affecting Dify versions up to 1.14.1, describing authorization bypass and path‑traversal weaknesses that may expose sensitive tenant data across boundaries.

    0002083
    196 followersView on X
  • solemsli@N_aBo_
    Disclosure

    2/ The lead bug, CVE-2026-41947 (CVSS 9.1): the tracing-config endpoints never verified which tenant owned the app. Point an accessible app from another org at your own trace provider and every AI message and response streams to you. A wiretap on their chats.

    Post summary

    The post announces CVE-2026-41947, a high‑severity flaw that allows cross‑tenant data interception via unverified tracing endpoints.

    1000065
    19 followersView on X
  • Aseem Shrey@AseemShrey
    Disclosure

    CVE-2026-41947 (CVSS 9.1) is even scarier in practice. The tracing system had no tenant validation. Any authenticated editor could configure tracing for ANY app on the instance. Not just their own. Any tenant's app. That means persistent, silent interception of every message and model response flowing through someone else's AI app.

    Post summary

    The post highlights a severe tenancy‑validation flaw in a tracing system, allowing any authenticated editor to silently intercept all messages and model responses across the instance. It focuses on the vulnerability’s details without mentioning a PoC, patch, or active exploitation evidence.

    10000195
    8.7K followersView on X
  • z3n@zench4n
    Disclosure

    Recent vulnerabilities highlight the risk. CVE-2026-41947 and CVE-2026-41948 in Dify show how authorization bypass and path traversal can compromise orchestration platforms.

    Post summary

    The post announces two new CVEs in Dify, detailing authorization bypass and path traversal flaws that could compromise orchestration platforms.

    1000037
    1.4K followersView on X
  • z3n@zench4n
    Disclosure

    Take Dify 1.14.1 as an example. CVE-2026-41947 demonstrates an authorization bypass, while CVE-2026-41948 shows how path traversal can be weaponized. When AI agents interact with local file systems or backend APIs, these flaws lead to full system compromise.

    Post summary

    The post announces that Dify 1.14.1 contains two CVEs—a 2026-41947 authorization bypass and a 2026-41948 path traversal—that can be weaponized by AI agents, potentially allowing full system compromise.

    100005
    1.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41947 Authorization Bypass in Dify 1.14.1 Allowing Unauthorized Trace Configuration Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41947

    Post summary

    The content announces CVE-2026-41947 as an authorization bypass in Dify 1.14.1, providing a brief description but no PoC, exploit, patch, or evidence of active use.

    0000059
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdifydify---

Explore more