Improper Authorization in n8n - #VU146790

 

Improper Authorization in n8n - #VU146790

Published: September 2, 2026


Vulnerability identifier: #VU146790
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete workflows and credentials across projects.

The vulnerability exists due to improper authorization in the source control push endpoint when processing a push request with file paths and status from the request payload. A remote privileged user can submit a crafted push request naming files from other projects to delete workflows and credentials across projects.

The issue is exploitable only when the Source Control (Environments) enterprise feature is licensed, enabled, and connected to a remote repository.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.76, 2.37.7, 2.38.2

External References

Related Security Bulletins