Junglewise Threat Intelligence

n8n privilege escalation in Enterprise SSO instance-role provisioning

Severity: high · CVSS 7.7 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool used to connect different software services. A security flaw in its Enterprise Single Sign-On (SSO) feature allows a user to be incorrectly assigned the 'Owner' role during login. If exploited, an attacker could gain full administrative control over the entire system, including access to all automated workflows, sensitive credentials, and user data.

Technical details

A privilege escalation vulnerability exists in n8n's Enterprise SSO instance-role provisioning logic. The application maps Identity Provider (IdP) role claims to internal global roles but fails to validate or restrict the 'global:owner' role during this specific provisioning path. An attacker who can influence the role claim returned by the IdP can elevate their privileges to instance owner. This requires Enterprise SSO to be configured and the 'N8N_SSO_SCOPES_PROVISION_INSTANCE_ROLE' environment variable to be enabled (it is disabled by default). The issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.

Affected products

  • n8n-io n8n < 1.123.64, < 2.29.8, < 2.30.1

Timeline

  • 2026-07-08: advisory: Original advisory GHSA-35q8-9mj6-wjmf published
  • 2026-07-22: disclosed: CVE-2026-65016 published

References

Related threats