Executive brief
n8n is a workflow automation tool used to connect different software applications. A security flaw in certain versions allows users with restricted 'viewer' permissions to perform actions they shouldn't be able to, such as starting, stopping, or deleting test runs of automated workflows. This could lead to unauthorized changes in workflow testing data or disruption of active test processes within an organization's environment.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in three mutating evaluation test-run endpoints within n8n. These endpoints incorrectly authorize state-changing actions using the 'workflow:read' scope instead of the required 'workflow:execute' scope. This flaw affects Enterprise and Cloud instances utilizing Advanced Permissions. An authenticated attacker with 'project:viewer' privileges can exploit this to initiate new evaluation test runs, cancel active runs, or delete run records for workflows they are only authorized to view. The issue is resolved in versions 1.123.55, 2.25.7, and 2.26.2.
Affected products
- n8n n8n < 1.123.55, < 2.25.7, < 2.26.2
Timeline
- 2026-06-10: advisory: Vendor advisory published on GitHub
- 2026-07-08: disclosed: CVE published to NVD