Junglewise Threat Intelligence

CVE-2026-65014: n8n missing authentication in test-webhook endpoint

CVE-2026-65014 · Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and test automated processes. An unauthenticated attacker can cancel any user's active test webhook by sending a specially crafted request if they know the workflow ID. While this disrupts testing activities, it does not affect production workflows, stored data, or system state, limiting the practical business impact.

Technical details

The vulnerability is a missing authentication check (CWE-306) on the DELETE /${restEndpoint}/test-webhook/:id REST API endpoint. The route is registered in the routing stack before the authentication middleware is applied, allowing unauthenticated network requests to reach it. An attacker who can obtain a workflow ID (e.g., through documentation, shared URLs, or enumeration) can send a DELETE request to cancel any active test webhook. The attack requires knowledge of the target workflow ID but no credentials or user interaction. The vulnerability does not affect production webhook registrations, persistent workflow state, or data stored in the system—only disrupts in-progress testing sessions. Patches are available in n8n versions 2.27.4 and 2.28.0 or later.

Affected products

  • n8n n8n < 2.27.4, < 2.28.0

Timeline

  • 2026-07-22: disclosed: GHSA-33q9-f52j-gc75 published
  • 2026-07-08: advisory: Advisory released on GitHub
  • 2026-06-24: patched: Fixed in n8n 2.27.4
  • 2026-06-23: patched: Fixed in n8n 2.28.0

References

Related threats