Authorization bypass through user-controlled key in Dify - #VU144401

 

Authorization bypass through user-controlled key in Dify - #VU144401

Published: August 19, 2026


Vulnerability identifier: #VU144401
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify MCP server configurations belonging to other applications in the same workspace.

The vulnerability exists due to improper access control in AppMCPServerController.put() when handling PUT requests to /console/api/apps//server. A remote user can send a crafted request with the ID of another application's MCP server to modify MCP server configurations belonging to other applications in the same workspace.

The issue affects applications within the same workspace.


Affected software

Dify

Remediation

Install security update from vendor's website.

Dify - update to 1.16.0

External References

Related Security Bulletins