Improper Authentication in n8n - CVE-2026-33665

 

Improper Authentication in n8n - CVE-2026-33665

Published: April 30, 2026


Vulnerability identifier: #VU128728
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33665
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain full access to another user's account.

The vulnerability exists due to improper authentication in LDAP account linking when matching an LDAP identity to an existing local account by email during login. A remote user can set their own LDAP email attribute to match another user's email and log in to gain full access to another user's account.

LDAP authentication must be configured and active, and the account linkage persists even if the LDAP email attribute is later reverted.


Affected software

n8n

How to mitigate CVE-2026-33665

Install security update from vendor's website.

n8n - addressed in versions 1.121.0, 2.4.0

External References

Related Security Bulletins