Improper access control in n8n - CVE-2026-54309

 

Improper access control in n8n - CVE-2026-54309

Published: June 16, 2026


Vulnerability identifier: #VU134559
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54309
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access browser-control capabilities and disclose sensitive information.

The vulnerability exists due to improper access control in the MCP HTTP transport endpoint when handling session initialization and tool invocation requests. A remote attacker can send crafted requests to access browser-control capabilities and disclose sensitive information.

Only instances running @n8n/mcp-browser with the HTTP transport enabled are affected. If the n8n AI Browser Bridge extension is installed and a browser connection is active, the issue can expose navigation, JavaScript evaluation, and access to browser cookies and storage in the user's real browser profile.


Affected software

n8n

How to mitigate CVE-2026-54309

Install security update from vendor's website.

n8n - addressed in versions 2.25.7, 2.26.2

External References

Related Security Bulletins