PT-2026-78934 · N8N · N8N

·

CVE-2026-77079

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.34.1 n8n versions prior to 2.33.4
Description An authorization bypass exists in the custom project role deletion and reassignment process. The system fails to perform project-level authorization checks when deleting a custom project role with a reassignment target, verifying only that the target role exists and is project-scoped. This allows a user with the role:manageProject global scope to delete any custom project role and reassign users, including themselves, to the built-in project:admin role, resulting in unauthorized administrative control over projects.
Recommendations Update to version 2.34.1 or later. Update to version 2.33.4 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77079
GHSA-XHMH-8FGR-XQHJ

Affected Products

N8N