Incorrect authorization in n8n - #VU153003

 

Incorrect authorization in n8n - #VU153003

Published: September 30, 2026


Vulnerability identifier: #VU153003
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform actions using credential values they are not authorized to use.

The vulnerability exists due to improper authorization validation in the shared-workflow credential check when saving a shared workflow containing nested inline workflows. A remote user can save a workflow with embedded nodes that reference inaccessible credentials to perform actions using credential values they are not authorized to use.

Inline workflows can be nested.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - update to 1.123.83

External References

Related Security Bulletins