PT-2026-48874 · N8N-Mcp · N8N-Mcp

CVE-2026-54052

·

Published

2026-06-12

·

Updated

2026-07-18

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions n8n-MCP versions prior to 2.56.1
Description An authorization flaw exists in n8n-MCP when operating in HTTP mode with multi-tenancy enabled via the ENABLE MULTI TENANT variable. In this configuration, local workflow version history backups are not isolated per tenant. This allows an authenticated tenant to read workflow version snapshots belonging to other tenants or delete and destroy their stored backups. These snapshots may contain sensitive information, including full node definitions, credential references, and authorization headers.
Recommendations Upgrade to version 2.56.1. As a temporary workaround, disable the workflow version tool by setting the DISABLED TOOLS variable to n8n workflow versions in the server environment. Avoid running the server in multi-tenant mode by serving each tenant from a separate instance with its own database. Restrict network access to the HTTP endpoint to trusted operators.

Exploit

Fix

RCE

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54052
GHSA-J6R7-6FHX-77WX

Affected Products

N8N-Mcp