PT-2026-63352 · N8N · N8N

CVE-2026-65594

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions n8n versions 2.27.0 through 2.29.7 n8n versions 2.30.0 through 2.30.0
Description The OAuth 2.1 consent and token-issuance flow fails to verify if the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client and self-approve consent for a workflow belonging to another user to obtain a valid token. This allows the workflow to execute within the owner's project context using the owner's stored credentials. Consequently, an attacker can manipulate tool inputs and read outputs, which may contain sensitive data from the owner's connected integrations, thereby bypassing user and project isolation.
Recommendations Update to version 2.29.8 or later. Update to version 2.30.1 or later. Restrict instance access to fully trusted users only. Audit active workflows using the MCP Server Trigger with n8n OAuth2 authentication and deactivate them or switch to a different authentication method.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65594
GHSA-5VFW-JC4P-FJ39
GHSA-Q5XF-XHWF-CWQF

Affected Products

N8N