CVE-2026-41947Dify · Dify
Vulnerability data via NVD (ingested)
Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to redirect all messages and responses from victim applications to attacker-controlled LLM trace providers. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-41947product:"Dify Dify"http.html:"Dify"More intel sources (5)
vuln:CVE-2026-41947vulnerabilities.cve_id: CVE-2026-41947CVE-2026-41947CVE-2026-41947"CVE-2026-41947" exploit -site:nvd.nist.gov