Improper access control in n8n - #VU146793

 

Improper access control in n8n - #VU146793

Published: September 2, 2026


Vulnerability identifier: #VU146793
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the Agent workflow tool path when invoking a workflow attached to an Agent as a tool. A remote user can attach or use a restricted workflow through an Agent to disclose sensitive information.

The workflow\'s \"This workflow can be called by\" setting is enforced for the Execute Workflow node but was not consulted on the Agent tool path.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 2.37.7, 2.38.2

External References

Related Security Bulletins