CVE-2026-41949Disclosure(dify / dify)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch dify dify systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api/files/{file_id}/preview endpoint with an intercepted file UUID to extract sensitive content from documents without ownership or workspace permission verification. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dify

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-18); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
dify

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-18: 1Mentions · 2026-06-22: 1Mentions · 2026-06-23: 1Mentions · 2026-07-06: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-22: 1Technical Details · 2026-06-23: 1Technical Details · 2026-07-06: 105-1806-2206-2307-06
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-181
Disclosure1
2026-06-221
Active Exploitation1
2026-06-231
Patch1
2026-07-061
Disclosure1
Full discourse4 posts
  • kokumօtօ@__kokumoto
    Patch

    Difyでテナント跨ぎでデータが漏洩する脆弱性群DifyTapについて。CVE-2024-5846、CVE-2026-41947、CVE-2026-41948、CVE-2026-41949、CVE-2026-41950。CVE-2026-41948は未修正。それ以外はバージョン1.14.2で修正。 https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html?m=1

    Post summary

    The post lists several CVEs for DifyTap, notes one remains unpatched while others were resolved in v1.14.2, and highlights a tenant‑crossing data leak without providing exploitation details.

    00020898
    7.7K followersView on X
  • solemsli@N_aBo_
    Disclosure

    4/ It goes further. CVE-2026-41949 lets you preview documents uploaded by other tenants with nothing but a file UUID. CVE-2026-41950 lets users read files uploaded by other users inside the same tenant. CVE-2026-41948 (CVSS 9.4) is a Plugin Daemon path traversal that can reach internal APIs.

    Post summary

    Three newly disclosed CVEs (CVE-2026-41949, CVE-2026-41950, CVE-2026-41948) are presented with their high‑severity capabilities: cross‑tenant document preview via UUID, intra‑tenant file read, and a path traversal reaching internal APIs, underscoring the need for immediate remediation.

    1000055
    19 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited authorization bypasses in Dify's multi-tenant AI platform to access private conversations across all tenants using only file UUIDs. The flaws (CVE-2026-41949, CVE-2026-21866) demonstrate how weak tenant isolation can turn single compromises into cross-customer data exposure. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/researchers-detail-difytap-flaws-in-dify-that-could-expose-ai-chats-across-tenants

    Post summary

    The analysis reveals that attackers exploited authorization bypasses in Dify’s multi‑tenant platform, exposing private conversations across tenants; no patch information is provided.

    0001072
    1.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41949 Authorization Bypass in Dify 1.14.1 File Preview Endpoint Across ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41949 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces an authorization bypass vulnerability (CVE‑2026‑41949) in Dify 1.14.1’s File Preview Endpoint, linking to a vulnerability database, but gives no details on patches, exploitation, or PoC.

    0000069
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdifydify---

Explore more