ADVISORY UNAUTH-2026-0012
TYPE exposure-class
PRODUCT Dify
SEVERITY CRITICAL
Dify console exposed to the internet
published 2026-08-05 · updated 2026-08-05
Why it matters
Your Dify admin console is reachable from the internet. If the setup never finished, the first visitor becomes admin and owns every app, prompt and model API key you configured. Even with setup finished, the console and its API sit one phished password away from a stranger.
What a probe sees
GET :5001/console/api/setup answers {"step": "not_started"} — the first visitor becomes admin.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
unclaimed-setup
In the wild
No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.
Fix it
References
Cite this record
unauth.dev advisory UNAUTH-2026-0012 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0012. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.