Improper access control in Dify - CVE-2026-34082
Published: July 27, 2026
Dify
Detailed vulnerability description
The vulnerability allows a remote user to delete another user's chat conversation.
The vulnerability exists due to improper access control in the DELETE /console/api/installed-apps/
Exploitation requires authentication, and any role is sufficient. Knowledge of the target conversation GUID is required.