CVE-2026-41949 Details
Description
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api/files/{file_id}/preview endpoint with an intercepted file UUID to extract sensitive content from documents without ownership or workspace permission verification. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
An authorization bypass vulnerability has been identified in Dify versions through 1.14.1. This vulnerability allows any authenticated user to access the first 3,000 characters of any uploaded document across all tenants and workspaces, using only the file's UUID. The issue arises in the file preview endpoint, where sensitive content can be extracted from documents without proper ownership or workspace permission verification. Dify Cloud's unauthenticated free self-registration further facilitates this exploitation.
Users can update to Dify version 1.14.2 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dify dify | <= 1.14.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | Reanalysis | [email protected] |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 18, 2026 | New CVE Received | [email protected] |