PT-2026-48874 · N8N-Mcp · N8N-Mcp
CVE-2026-54052
·
Published
2026-06-12
·
Updated
2026-07-18
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
n8n-MCP versions prior to 2.56.1
Description
An authorization flaw exists in n8n-MCP when operating in HTTP mode with multi-tenancy enabled via the
ENABLE MULTI TENANT variable. In this configuration, local workflow version history backups are not isolated per tenant. This allows an authenticated tenant to read workflow version snapshots belonging to other tenants or delete and destroy their stored backups. These snapshots may contain sensitive information, including full node definitions, credential references, and authorization headers.Recommendations
Upgrade to version 2.56.1.
As a temporary workaround, disable the workflow version tool by setting the
DISABLED TOOLS variable to n8n workflow versions in the server environment.
Avoid running the server in multi-tenant mode by serving each tenant from a separate instance with its own database.
Restrict network access to the HTTP endpoint to trusted operators.Exploit
Fix
RCE
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
N8N-Mcp