CVE-2026-28288

MEDIUM NUCLEI

Dify < 1.9.0 - Email Enumeration via Observable Response Discrepancy

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-28288 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

Nuclei Templates (1)

Dify User Enumeration via Observable Response Discrepancy
MEDIUMVERIFIEDby DhiyaneshDk

References (2)

Core 2
Core References
Issue Tracking x_refsource_misc
https://github.com/langgenius/dify/issues/24323

Scores

CVSS v3 5.3
EPSS 0.0045
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-204
Status published
Products (1)
dify/dify < 1.9.0
Published Feb 27, 2026
Tracked Since Feb 28, 2026