Executive brief
n8n is a workflow automation tool used to connect different software services. A security flaw allows unauthorized individuals to cancel active test sessions for webhooks if they know the specific workflow ID. While this can disrupt development and testing activities, it does not affect production workflows, stored customer data, or the overall security of the system.
Technical details
The vulnerability exists because the 'DELETE /${restEndpoint}/test-webhook/:id' route is registered before authentication middleware is applied. An unauthenticated attacker with knowledge of a specific workflow ID can send a DELETE request to this endpoint to terminate an active test webhook registration. This is classified as a missing authentication for a critical function (CWE-306). The impact is limited to the availability of in-progress test sessions; production webhooks and persistent data remain unaffected. The issue is resolved in versions 2.28.0 and 2.27.4.
Affected products
- n8n-io n8n < 2.28.0, < 2.27.4 (on 2.27.x branch)
Timeline
- 2026-07-08: advisory: Original GHSA-33q9-f52j-gc75 published
- 2026-07-22: disclosed: CVE-2026-65014 published to NVD