PT-2026-63352 · N8N · N8N
CVE-2026-65594
·
Published
2026-07-22
·
Updated
2026-07-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
n8n versions 2.27.0 through 2.29.7
n8n versions 2.30.0 through 2.30.0
Description
The OAuth 2.1 consent and token-issuance flow fails to verify if the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with
n8n OAuth2 authentication, a member-level user can register an OAuth client and self-approve consent for a workflow belonging to another user to obtain a valid token. This allows the workflow to execute within the owner's project context using the owner's stored credentials. Consequently, an attacker can manipulate tool inputs and read outputs, which may contain sensitive data from the owner's connected integrations, thereby bypassing user and project isolation.Recommendations
Update to version 2.29.8 or later.
Update to version 2.30.1 or later.
Restrict instance access to fully trusted users only.
Audit active workflows using the MCP Server Trigger with
n8n OAuth2 authentication and deactivate them or switch to a different authentication method.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N