Skip to main content
QUIETLYTIC
Vulnerability

6 n8n CVEs (CVE-2026-86073)

Six n8n access-control CVEs: an OAuth consent-scope bypass, an approval-gate bypass, and four cross-user data-disclosure flaws.

CVE-2026-86073
Threat Level
HIGH
CVSS
7.6
Status
Monitored
Confidence
Medium
Affected Products
n8n

Full CVE Roster

All 6 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search.

CVE ID Title CVSS Severity KEV
CVE-2026-86073 — 7.6 high
CVE-2026-86077 — 6.5 medium
CVE-2026-86996 — 5.4 medium
CVE-2026-86085 — 4.9 medium
CVE-2026-86993 — 4.9 medium
CVE-2026-86994 — 4.3 medium

Six n8n CVEs disclosed in September 2026 share a single root failure mode: a scope, ownership, or caller-policy check that existed for the normal path but was missing from a secondary or newer code path — an OAuth refresh that skipped the original consent scope, a chat resume token honored outside its intended flow, and four separate endpoints that returned or acted on data belonging to a project, credential, or workflow the caller didn’t actually have rights to. All six trace to NVD and GitHub Advisory Database records whose text is near-identical (NVD relaying the same GitHub-Advisory-CNA-supplied analysis), so we’re scoring confidence medium throughout rather than treating the two source IDs as independent corroboration.

Per the GitHub Advisory Database record, n8n’s OAuth token endpoint bound the access token issued on a first grant to the resource the user consented to, but the accompanying refresh token wasn’t bound the same way. On refresh, the server checked only that the requested resource was registered on the instance — not that it matched what was originally consented to. CWE-863 (Incorrect Authorization). CVSS base 7.6 (high; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N). Impact: an OAuth client approved for one protected workflow could refresh its way into a valid access token for a second, unapproved workflow the consenting user has access to, exceeding its granted consent scope. Fixed in 2.37.7 and 2.38.1. Confidence: medium.

CVE-2026-86077: anonymous approval-gate bypass via reused chat resume token

Per the GitHub Advisory Database record, the /chat WebSocket route’s resume logic accepted a resume token and resumed a paused workflow execution without verifying the target node actually supported chat-based resumption. Because resume tokens are also issued to anonymous form submitters for legitimate chat flows, the same token could be replayed against non-chat wait/approval node types. CWE-862 (Missing Authorization). CVSS base 6.5 (medium; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Impact: a party with no account, holding only a resume token issued for an anonymous form submission, could release an execution paused at a human approval gate — bypassing a control the workflow author deliberately put in place. Fixed in 2.37.7 and 2.38.2. Confidence: medium.

CVE-2026-86996: agent workflow tool bypasses sub-workflow caller policy

Per the GitHub Advisory Database record, a workflow’s “this workflow can be called by” restriction is normally enforced by the standard Execute Workflow node, but the code path used when the same workflow is attached to an AI Agent as a callable tool omitted the corresponding caller-policy check. CWE-862 (Missing Authorization). CVSS base 5.4 (medium; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Impact: a user able to configure an Agent could invoke a workflow its owner had restricted to specific callers, and read the data it returned, bypassing the caller-policy restriction. Fixed in 2.37.7 and 2.38.2. Confidence: medium.

CVE-2026-86085: cross-project member PII disclosure via missing per-project scope check

Per the GitHub Advisory Database record, n8n’s role-assignment endpoints checked only that the caller held permission to manage a given role type, without also verifying the caller had visibility into the specific project named in the request. CWE-862 (Missing Authorization). CVSS base 4.9 (medium; vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). Impact: a user holding role-management permission, but not membership in a given project, could name that project directly and read back its members’ names and email addresses. Fixed in 2.37.7 and 2.38.2. Confidence: medium.

CVE-2026-86993: log streaming decrypts generic-auth credentials without an ownership check

Per the GitHub Advisory Database record, a Log Streaming event destination could reference a generic HTTP credential by ID, and the destination-resolution logic decrypted whichever credential ID it was given without verifying the caller actually had read access to that specific credential. CWE-862 (Missing Authorization). CVSS base 4.9 (medium; vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). Impact: a user with a custom global role granting Log Streaming permissions could name a credential belonging to a different project and have its decrypted secret sent to a destination endpoint of their choosing. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

CVE-2026-86994: cross-user active workflow ID and lifecycle event disclosure

Per the GitHub Advisory Database record, the active-workflows endpoint returned the IDs of every active workflow on the instance to any authenticated member, without filtering by sharing permissions, and workflow activation/deactivation/publication events were broadcast to all connected clients regardless of access. CWE-862 (Missing Authorization). CVSS base 4.3 (medium; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Impact: any authenticated member could see workflow IDs, version IDs, and activation-error details for workflows they had no sharing access to. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

Confidence and evidence gaps

All six CVEs carry both an NVD and a GitHub Advisory Database row in our ledger, but the text is near-identical across the pair in every case — NVD condensing the same GitHub-Advisory-CNA-supplied analysis rather than contributing independent findings. We’re scoring confidence medium across the board on that basis, not high, even though the ledger technically shows two source IDs per claim. Five of the six (86077, 86996, 86085, 86993, 86994) share CWE-862 (Missing Authorization) as their root weakness class — the same fix release (2.37.7/2.38.2) across nearly all six reads as a coordinated authorization-hardening pass rather than six unrelated discoveries, an inference from the shared fix versions rather than something the records state outright.

Why this matters

Every one of these six flaws is the same shape: a permission check exists somewhere in the codebase, but a newer or secondary code path — an Agent-tool invocation, a WebSocket resume route, a credential-destination lookup — didn’t call it. That’s the same underlying lesson as our CodeWhale AI coding-agent roundup: adding a new way to trigger existing functionality (an Agent tool wrapping a workflow, a chat interface wrapping an approval gate) is also adding a new place a security check has to be re-applied, not assumed. Teams building agent-callable tools on top of an existing permission model should specifically audit every new entry point against the checks the “normal” path already enforces, rather than trusting that a shared underlying function makes the check automatic.

Frequently Asked Questions

Are any of these six vulnerabilities being actively exploited? No. None are listed in any KEV catalog, and our source data contains no exploitation reports for any of them.

Which of these six is the most severe? CVE-2026-86073, CVSS 7.6 — the OAuth refresh-token consent-scope bypass, the only one of the six rated high rather than medium severity.

Do these require administrator-level access to exploit? No — per the records, all six are exploitable by an ordinary authenticated user or, in CVE-2026-86077’s case, an anonymous party holding a resume token from an unrelated legitimate flow. None require administrative privileges.

Which n8n versions fix all six? CVE-2026-86073 is fixed in 2.37.7 and 2.38.1. The other five are fixed in 2.37.7 and 2.38.2 (86993 and 86994’s fix also lands in 1.123.76) — instances should update to whichever line matches their current branch.


Data sourced from the National Vulnerability Database (NVD) and the GitHub Advisory Database, evaluated September 2026. This product uses the NVD API but is not endorsed or certified by the NVD. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 GitHub Advisory Database

Related intelligence


Analyst tools