Junglewise Threat Intelligence

CVE-2026-77079: n8n authorization bypass in custom project role deletion

CVE-2026-77079 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows organizations to automate business processes and integrate applications. A flaw in the custom project role deletion feature allows a user with limited administrative permissions to delete any custom role across the entire instance and reassign affected users—including themselves—to the built-in admin role, gaining unauthorized full administrative access to projects they should not have access to. This could enable account takeover and complete compromise of project data and configurations.

Technical details

The vulnerability is an authorization bypass (CWE-639) in the custom project role deletion and reassignment endpoint. When a user deletes a custom project role with a reassignment target, the code validates that the target role exists and is project-scoped, but fails to perform project-level authorization checks. An attacker with the narrow role:manageProject global scope can exploit this to delete any custom project role in use on the instance and reassign its holders to the built-in project:admin role. The attack requires authentication (low privilege user) and network access but no user interaction. The vulnerability has been patched in n8n versions 2.34.1 and 2.33.4.

Affected products

  • n8n n8n before 2.34.1 and before 2.33.4

Timeline

  • 2026-08-20: disclosed
  • 2026-08-05: patched: Patched in versions 2.34.1 and 2.33.4

References

Related threats