PT-2026-63346 · N8N · N8N
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.64
n8n versions prior to 2.29.8
n8n versions prior to 2.30.1
Description
A privilege escalation issue exists in Enterprise SSO instance-role provisioning. The provisioning path maps an Identity Provider (IdP) asserted role claim to an n8n global role but fails to prevent the assignment of the
global:owner role. Consequently, an SSO-authenticated user whose instance-role claim resolves to global:owner is provisioned as an instance owner, granting full administrative control over workflows, credentials, users, and instance configuration. This issue is exploitable when Enterprise SSO is configured and instance-role provisioning is enabled via the N8N SSO SCOPES PROVISION INSTANCE ROLE variable. Exploitation requires the attacker to control the instance-role claim value issued by the IdP.Recommendations
Update to version 1.123.64 or later.
Update to version 2.29.8 or later.
Update to version 2.30.1 or later.
Disable instance-role provisioning by unsetting or setting
N8N SSO SCOPES PROVISION INSTANCE ROLE=false.
Audit IdP claim mappings to ensure no user-controllable attribute can supply the instance-role claim value.
Restrict SSO access to fully trusted users only.Exploit
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N