Junglewise Threat Intelligence

n8n missing authentication in test-webhook endpoint

Severity: medium · CVSS 6.3 · Published 2026-07-22

Technologies: N8n-Io N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool used to connect different software services. A security flaw allows unauthorized individuals to cancel active test sessions for webhooks if they know the specific workflow ID. While this can disrupt development and testing activities, it does not affect production workflows, stored customer data, or the overall security of the system.

Technical details

The vulnerability exists because the 'DELETE /${restEndpoint}/test-webhook/:id' route is registered before authentication middleware is applied. An unauthenticated attacker with knowledge of a specific workflow ID can send a DELETE request to this endpoint to terminate an active test webhook registration. This is classified as a missing authentication for a critical function (CWE-306). The impact is limited to the availability of in-progress test sessions; production webhooks and persistent data remain unaffected. The issue is resolved in versions 2.28.0 and 2.27.4.

Affected products

  • n8n-io n8n < 2.28.0, < 2.27.4 (on 2.27.x branch)

Timeline

  • 2026-07-08: advisory: Original GHSA-33q9-f52j-gc75 published
  • 2026-07-22: disclosed: CVE-2026-65014 published to NVD

References

Related threats