Junglewise Threat Intelligence

CVE-2026-65016: n8n privilege escalation in Enterprise SSO instance-role provisioning

CVE-2026-65016 · Severity: high · CVSS 4 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that supports enterprise single sign-on (SSO) for user authentication and role assignment. A flaw in the instance-role provisioning feature fails to prevent SSO users from being assigned the owner role, even if a lower-privileged user can influence the IdP claim. An attacker who controls the instance-role claim value can gain full administrative access to all workflows, credentials, user accounts, and system configuration.

Technical details

The vulnerability exists in n8n's Enterprise SSO instance-role provisioning path, which maps identity provider (IdP) role claims to n8n global roles during authentication. Unlike the token-exchange identity provisioning path (which explicitly rejects owner role assignment), the instance-role path does not validate that the global:owner role is prevented from being assigned. This allows an SSO-authenticated user whose IdP-asserted instance-role claim maps to global:owner to be provisioned with full instance owner privileges. Exploitation requires three preconditions: (1) Enterprise SSO must be configured, (2) instance-role provisioning must be explicitly enabled via the N8N_SSO_SCOPES_PROVISION_INSTANCE_ROLE environment flag (disabled by default), and (3) the attacker must be able to control or influence the instance-role claim value issued by the IdP. The latter typically requires control over the IdP configuration, claim-to-role mappings, or a permissive IdP setup. The vulnerability was fixed in versions 1.123.64, 2.29.8, and 2.30.1.

Affected products

  • n8n n8n All versions before 1.123.64, 2.29.8, and 2.30.1; specifically <1.123.64, 2.0.0-rc.0 to <2.29.8, 2.30.0

Timeline

  • 2026-07-22: disclosed: Advisory GHSA-35q8-9mj6-wjmf published
  • 2026-07-08: patched: Fixed in versions 1.123.64, 2.29.8, and 2.30.1

References

Related threats