CVE-2026-41947: Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant owne...

Added to the CISA Known Exploited Vulnerabilities catalog on 18 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.1.

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to...

Required action: Review and patch if applicable to your AI infrastructure.