← advisory ledger

ADVISORY UNAUTH-2026-0012
TYPE exposure-class
PRODUCT Dify
SEVERITY CRITICAL

CRITICAL

Dify console exposed to the internet

published 2026-08-05 · updated 2026-08-05

Why it matters

Your Dify admin console is reachable from the internet. If the setup never finished, the first visitor becomes admin and owns every app, prompt and model API key you configured. Even with setup finished, the console and its API sit one phished password away from a stranger.

What a probe sees

GET :5001/console/api/setup answers {"step": "not_started"} — the first visitor becomes admin.

Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).

unclaimed-setup

In the wild

No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.

Fix it

Fix card: dify-exposed →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0012 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0012. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.