PT-2026-63346 · N8N · N8N

·

CVE-2026-65016

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.64 n8n versions prior to 2.29.8 n8n versions prior to 2.30.1
Description A privilege escalation issue exists in Enterprise SSO instance-role provisioning. The provisioning path maps an Identity Provider (IdP) asserted role claim to an n8n global role but fails to prevent the assignment of the global:owner role. Consequently, an SSO-authenticated user whose instance-role claim resolves to global:owner is provisioned as an instance owner, granting full administrative control over workflows, credentials, users, and instance configuration. This issue is exploitable when Enterprise SSO is configured and instance-role provisioning is enabled via the N8N SSO SCOPES PROVISION INSTANCE ROLE variable. Exploitation requires the attacker to control the instance-role claim value issued by the IdP.
Recommendations Update to version 1.123.64 or later. Update to version 2.29.8 or later. Update to version 2.30.1 or later. Disable instance-role provisioning by unsetting or setting N8N SSO SCOPES PROVISION INSTANCE ROLE=false. Audit IdP claim mappings to ensure no user-controllable attribute can supply the instance-role claim value. Restrict SSO access to fully trusted users only.

Exploit

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65016
GHSA-35Q8-9MJ6-WJMF
GHSA-MWQ7-VCMC-CM4Q

Affected Products

N8N