Junglewise Threat Intelligence

CVE-2026-65594: n8n incorrect authorization in OAuth 2.1 flow for MCP Server Triggers

CVE-2026-65594 · Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform used to connect different business applications. A security flaw allows users with low-level access to bypass authorization checks and execute automated tasks belonging to other users, including administrators. This could allow an attacker to access sensitive data from connected integrations or perform actions using another user's high-level credentials without their knowledge.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in n8n's OAuth 2.1 consent and token-issuance flow. The system fails to verify if an authenticated user has permission to access the specific workflow requested as an OAuth resource. A member-level attacker can register an OAuth client and self-approve consent for another user's 'n8n OAuth2'-protected MCP Server Trigger workflow. This allows the attacker to obtain a valid token and execute the workflow within the victim's project context, utilizing the victim's stored credentials and accessing their connected integration data. The issue is fixed in versions 2.29.8 and 2.30.1.

Affected products

  • n8n-io n8n >= 2.27.0, < 2.29.8; >= 2.30.0, < 2.30.1

Timeline

  • 2026-07-08: disclosed: Initial disclosure by n8n-io
  • 2026-07-22: advisory: GitHub Advisory published and CVE assigned

References

Related threats