Improper access control in n8n - #VU134563

 

Improper access control in n8n - #VU134563

Published: June 16, 2026


Vulnerability identifier: #VU134563
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to trigger workflow execution and cause unintended side effects in downstream systems.

The vulnerability exists due to improper access control in the POST /workflows/{workflowId}/test-runs/new endpoint when handling requests to create evaluation test runs. A remote user can send a request to create a new test run for a workflow with read-only access to trigger workflow execution and cause unintended side effects in downstream systems.

Only instances using the Evaluations feature are affected.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.55, 2.25.7, 2.26.2

External References

Related Security Bulletins