Missing Authentication for Critical Function in n8n - #VU137156
Published: July 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access control in the DELETE /${restEndpoint}/test-webhook/:id endpoint when handling unauthenticated requests. A remote attacker can send a crafted request with a known workflow ID to cause a denial of service.
The impact is limited to disrupting in-progress test sessions. Production webhooks, persistent workflow state, and stored data are not affected.