Improper Authorization in n8n - #VU134556
Published: June 16, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to modify evaluation test runs and cause a denial of service.
The vulnerability exists due to improper access control in evaluation test runs controller endpoints when handling state-changing requests. A remote user can send requests to start new evaluation test runs, cancel in-flight runs, or delete run records to modify evaluation test runs and cause a denial of service.
This issue only affects instances with Advanced Permissions where projects and viewer roles are in use.