A vulnerability, which was classified as problematic, has been found in langgenius dify up to 1.13.x. The affected element is an unknown function. Performing a manipulation results in authorization bypass.

This vulnerability is reported as CVE-2026-41950. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.