Executive brief
n8n is a workflow automation tool used to connect various business applications. A security flaw allows users who have already logged in via Single Sign-On (SSO) to disable SSO requirements for their own accounts. This allows a user to create a local password and log in directly, bypassing company security policies such as multi-factor authentication (MFA) and centralized identity management.
Technical details
An improper authorization vulnerability (CWE-285) in the n8n API allows an authenticated user who signed in via Single Sign-On (SSO) to disable SSO enforcement for their own account. By interacting with the API, the user can circumvent organizational identity provider policies and create local password credentials. This enables direct authentication via email and password, effectively bypassing MFA and other centralized security controls enforced by the SSO provider. The vulnerability is present in versions prior to 2.8.0 and requires the attacker to have valid low-privileged SSO credentials to initiate the bypass.
Affected products
- n8n n8n < 2.8.0
Timeline
- 2026-02-25: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: CVE published to NVD