Vulnerability  ·  2026-10-07

Dify MCP server cross-application authorization bypass (CVE-2026-105761)

VulnerabilityMedium impactGlobalCVE-2026-105761
The PUT /console/api/apps/<app_id>/server endpoint retrieves an AppMCPServer by client-supplied server ID without verifying tenant/application ownership. An authenticated workspace member can change another application's MCP server status and parameters — redirecting data flows or disabling the service. Fixed in 1.16.0.
MCP server config is the agent data path in Dify apps; cross-app tampering lets a workspace member redirect another app's agent tool traffic or knock it offline.
Authenticated PUT to the app MCP server endpoint with a server ID belonging to another application/tenant.
Dify (langgenius/dify) < 1.16.0
Upgrade to Dify 1.16.0.
NVD CVE-2026-105761GitHub advisory GHSA-ccrj-frp2-c945
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →