SB20260819145 - Authorization bypass through user-controlled key in Dify



SB20260819145 - Authorization bypass through user-controlled key in Dify

Published: August 19, 2026

Security Bulletin ID SB20260819145
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authorization bypass through user-controlled key (CVE-ID: N/A)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify MCP server configurations belonging to other applications in the same workspace.

The vulnerability exists due to improper access control in AppMCPServerController.put() when handling PUT requests to /console/api/apps//server. A remote user can send a crafted request with the ID of another application's MCP server to modify MCP server configurations belonging to other applications in the same workspace.

The issue affects applications within the same workspace.


Remediation

Install update from vendor's website.