CVE-2026-105761 | Langgenius Dify up to 1.15.x MCP Server Management mcp_server.py AppMCPServerController.put server_id privileges management (EUVD-2026-92852)

SecurityVulns

A vulnerability classified as problematic was found in Langgenius Dify up to 1.15.x. Affected by this issue is the function AppMCPServerController.put of the file api/controllers/console/app/mcp_server.py of the component MCP Server Management. Executing a manipulation of the argument server_id can lead to improper privilege management.

The identification of this vulnerability is CVE-2026-105761. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More