Authentication Bypass by Spoofing in n8n - CVE-2026-54308
Published: June 16, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote attacker to execute workflows with attacker-controlled data.
The vulnerability exists due to authentication bypass by spoofing in the MicrosoftAgent365Trigger and StripeTrigger nodes when handling inbound webhook requests. A remote attacker can submit a forged payload to execute workflows with attacker-controlled data.
Exploitation requires knowledge of the webhook URL.