← back
CVE-2026-41949highCWE-639

Dify < 1.14.2 Authorization Bypass via File Preview Endpoint

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.2epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api/files/{file_id}/preview endpoint with an intercepted file UUID to extract sensitive content from documents without ownership or workspace permission verification. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
langgenius · dify
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.