Improper access control in Dify - #VU139797
Published: July 27, 2026
Dify
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the /use-check endpoint when handling requests for external API usage checks. A remote user can send a request for another tenant's external API template UUID to disclose sensitive information.
The issue can reveal whether a target external API template is in use and how many datasets reference it across tenants.