Improper Authorization in n8n - #VU134572

 

Improper Authorization in n8n - #VU134572

Published: June 16, 2026


Vulnerability identifier: #VU134572
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authorization checks and retry workflow executions.

The vulnerability exists due to improper access control in the Public API execution retry endpoint when handling retry requests for shared workflows. A remote user can send a retry execution request for a workflow with only read access to bypass authorization checks and retry workflow executions.

This issue affects instances where workflows are shared with other users or across projects.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 2.25.7, 2.26.2

External References

Related Security Bulletins