CVE-2026-28288: Dify has a user enumeration issue
Published Feb 27, 2026
·Updated
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.
Affected Software
2 affected components
Dify dify<1.9.0
Dify dify<1.9.0
Event History
Feb 27, 2026
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Dec 1, 58158
Event
via FIRST·09:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-28288?
CVE-2026-28288 is classified as a medium severity vulnerability due to its potential for user enumeration.
2
How do I fix CVE-2026-28288?
To fix CVE-2026-28288, upgrade to Dify version 1.9.0 or later.
3
What type of vulnerability is CVE-2026-28288?
CVE-2026-28288 is an enumeration vulnerability that allows attackers to differentiate between existing and non-existent accounts.
4
Who is affected by CVE-2026-28288?
Users of Dify prior to version 1.9.0 are affected by CVE-2026-28288.
5
What can attackers do with CVE-2026-28288?
Attackers can use CVE-2026-28288 to enumerate and validate email addresses registered with the Dify platform.