Junglewise Threat Intelligence

n8n improper authorization in workflow folder assignment

Severity: medium · CVSS 5 · Published 2026-07-08

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool used to connect different software applications. A security flaw in versions prior to 2.28.0 allows logged-in users to incorrectly link their automation workflows to folders belonging to other projects they do not own. While this does not expose private data or grant access to other users' work, it can disrupt how projects are organized and managed within the system.

Technical details

n8n before version 2.28.0 is vulnerable to an improper authorization bypass (CWE-639) when multi-project and folder support is enabled. An authenticated attacker with workflow creation permissions can supply a crafted request payload to associate a new workflow with a folder ID belonging to a different project. While the attacker does not gain access to the target project's data and the workflow remains in the attacker's project, this results in a logical integrity violation of the target project's folder structure at the database level. The issue is resolved in version 2.28.0.

Affected products

  • n8n n8n < 2.28.0

Timeline

  • 2026-06-24: advisory: Original advisory GHSA-2xgm-wc4g-5jvg published
  • 2026-07-08: disclosed: NVD publication of CVE-2026-59253
  • 2026-07-22: other: Duplicate advisory GHSA-gqcv-rfj6-r29g withdrawn

References

Related threats