Improper Authorization in n8n - #VU140998
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the custom-role deletion reassignment path when handling role deletion requests with a reassignment target. A remote user can delete a custom project role and reassign its holders to the built-in project:admin role to escalate privileges.
Exploitation requires the global role:manageProject scope.