← Vulnerability feed

Vulnerability record · CVE-2026-28288 · published 27 February 2026

CVE-2026-28288: Dify vulnerability

Dify · Dify

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

5.5 CVSS 4.0 Medium EPSS 0.71% · top 48.3% CWE-204 · CWE-204
5.5CVSS 4.0 base score
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28288 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-41947Dify insecure direct object reference vulnerabilityDify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio…EPSS 0.61%9.3CVE-2026-41948Dify relative path traversal vulnerabilityDify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin D…EPSS 1.9%8.8CVE-2025-0185Dify code injection vulnerabilityA vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vuln…EPSS 1.1%8.7CVE-2026-61461Dify sql injection vulnerabilityDify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by s…EPSS 0.50%8.4CVE-2025-67732Dify information exposure vulnerabilityDify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin…EPSS 0.35%8.2CVE-2026-41949Dify insecure direct object reference vulnerabilityDify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up …EPSS 0.57%7.5CVE-2024-11822Dify server-side request forgery (ssrf) vulnerabilitylanggenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the a…EPSS 0.60%5.3CVE-2026-34082Dify improper access control vulnerabilityDify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<appId>/conversations/<conversat…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-28288), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.