Junglewise Threat Intelligence

CVE-2026-56353: n8n authentication bypass in Chat Trigger node

CVE-2026-56353 · Severity: medium · CVSS 4.8 · Published 2026-07-15

Technologies: N8n. Vendors: N8n.

Executive brief

n8n, a popular workflow automation platform, contains a security flaw in its Chat Trigger component. When specifically configured to use n8n User Auth, an attacker can bypass the login requirements to interact with the chat interface without valid credentials. This could allow unauthorized individuals to trigger automated workflows or access sensitive data processed by the chat node.

Technical details

An authentication bypass vulnerability (CWE-287) exists in the n8n Chat Trigger node. The flaw occurs when the node is configured with 'n8n User Auth', which is a non-default setting. In affected versions, the authentication check on the Chat Trigger webhook endpoint can be circumvented by a remote, unauthenticated attacker. This allows the attacker to interact with the webhook without providing valid credentials. The vulnerability is fixed in versions 1.123.22, 2.9.3, and 2.10.1. As a workaround, users can switch to a different authentication method or restrict network access to the webhook endpoint.

Affected products

  • n8n n8n < 1.123.22, 2.0.0 - 2.9.2, 2.10.0

Timeline

  • 2026-02-25: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: NVD publication date

References

Related threats