Improper access control in n8n - #VU146793
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Agent workflow tool path when invoking a workflow attached to an Agent as a tool. A remote user can attach or use a restricted workflow through an Agent to disclose sensitive information.
The workflow\'s \"This workflow can be called by\" setting is enforced for the Execute Workflow node but was not consulted on the Agent tool path.