Improper access control in n8n - #VU146791
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to obtain a valid session.
The vulnerability exists due to improper access control in the public OIDC login and callback endpoints when handling OIDC authentication requests. A remote user can send requests to the endpoints to obtain a valid session.
The issue affects enterprise instances where OIDC was configured at least once and later disabled.