CVE-2026-41950: exploitation status and patch state

CVE-2026-41950 · CVSS 6.5 MEDIUM · EPSS <1%

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership validation, bypassing workspace separation and signed URL protections to retrieve sensitive file contents through workflow processing.

Is CVE-2026-41950 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-41950

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.