Observable Response Discrepancy in Dify - CVE-2026-28288
Published: July 27, 2026
Dify
Detailed vulnerability description
The vulnerability allows a remote attacker to enumerate registered email addresses.
The vulnerability exists due to observable response discrepancy in the /console/api/login endpoint when handling login requests. A remote attacker can send crafted login requests with candidate email addresses to enumerate registered email addresses.
The issue can be identified by differences in API responses for existing accounts versus non-existent accounts.