Junglewise Threat Intelligence

CVE-2026-59253: n8n improper authorization in workflow folder assignment

CVE-2026-59253 · Severity: medium · CVSS 4 · Published 2026-07-08

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform used to create and manage automated business processes. An authenticated user can bypass security controls and associate workflows with folders in projects they don't have access to, compromising the logical integrity of the folder structure in those projects. While the attacker's workflow remains in their own project and no data is exposed, this violation can disrupt project organization and management.

Technical details

This is an improper authorization vulnerability (CWE-639) in n8n's workflow creation API that allows authenticated users to bypass project and folder access controls. The vulnerability exists in the workflow folder assignment logic during workflow creation, where insufficient validation of the parentFolderId parameter permits users to reference folders in projects they lack permissions for. An attacker with workflow creation privileges in one project can craft a malicious API request containing a folder ID from a different project, causing the newly created workflow to be associated with that unauthorized folder, though the workflow itself remains in the attacker's project. The impact is limited to logical integrity violations in the target project's folder structure at the database level—no data exposure or folder ownership changes occur. This only affects n8n instances with multi-project and folder support enabled. The vulnerability was fixed in version 2.28.0 through improved validation of parent folder IDs in the workflow creation endpoint.

Affected products

  • n8n n8n < 2.28.0

Timeline

  • 2026-07-22: disclosed
  • 2026-06-23: patched: Fixed in n8n version 2.28.0

References

Related threats