PT-2026-22397 · Dify · Dify

Kast3T

·

Published

2026-02-27

·

Updated

2026-03-27

·

CVE-2026-28288

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dify versions prior to 1.9.0
Description The Dify API exhibits differing responses when queried for existing and non-existent accounts, potentially enabling an attacker to enumerate email addresses registered with the Dify platform. This issue affects the application's ability to protect user information.
Recommendations Update to version 1.9.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28288
GHSA-9QPF-WCV3-W3QX

Affected Products

Dify