Executive brief
n8n is a workflow automation platform that supports enterprise single sign-on (SSO) for user authentication and role assignment. A flaw in the instance-role provisioning feature fails to prevent SSO users from being assigned the owner role, even if a lower-privileged user can influence the IdP claim. An attacker who controls the instance-role claim value can gain full administrative access to all workflows, credentials, user accounts, and system configuration.
Technical details
The vulnerability exists in n8n's Enterprise SSO instance-role provisioning path, which maps identity provider (IdP) role claims to n8n global roles during authentication. Unlike the token-exchange identity provisioning path (which explicitly rejects owner role assignment), the instance-role path does not validate that the global:owner role is prevented from being assigned. This allows an SSO-authenticated user whose IdP-asserted instance-role claim maps to global:owner to be provisioned with full instance owner privileges. Exploitation requires three preconditions: (1) Enterprise SSO must be configured, (2) instance-role provisioning must be explicitly enabled via the N8N_SSO_SCOPES_PROVISION_INSTANCE_ROLE environment flag (disabled by default), and (3) the attacker must be able to control or influence the instance-role claim value issued by the IdP. The latter typically requires control over the IdP configuration, claim-to-role mappings, or a permissive IdP setup. The vulnerability was fixed in versions 1.123.64, 2.29.8, and 2.30.1.
Affected products
- n8n n8n All versions before 1.123.64, 2.29.8, and 2.30.1; specifically <1.123.64, 2.0.0-rc.0 to <2.29.8, 2.30.0
Timeline
- 2026-07-22: disclosed: Advisory GHSA-35q8-9mj6-wjmf published
- 2026-07-08: patched: Fixed in versions 1.123.64, 2.29.8, and 2.30.1
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-35q8-9mj6-wjmf
- https://github.com/n8n-io/n8n
- https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.64
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.29.8
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.30.1
- https://www.vulncheck.com/advisories/n8n-before-privilege-escalation-via-sso-instance-role