Junglewise Threat Intelligence

n8n unauthenticated endpoint allows test webhook cancellation

Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and manage automated tasks. An unauthenticated vulnerability in n8n allows anyone on the network who knows a workflow ID to cancel that workflow's active test webhook, disrupting in-progress testing sessions. This does not affect production webhooks or stored data, but can interfere with legitimate testing and debugging work.

Technical details

The vulnerability exists in the DELETE /${restEndpoint}/test-webhook/:id endpoint, which is registered before authentication middleware is applied in n8n versions before 2.28.0 (and 2.27.4 on the 2.27.x branch). This authorization bypass (CWE-306) allows any unauthenticated network attacker with knowledge of a workflow ID to send a DELETE request and cancel test webhook registrations. The attack requires network access to the n8n instance but no authentication credentials or user interaction. The impact is limited to service disruption of test sessions; production webhooks, workflow state, and persisted data remain unaffected. Patches are available in n8n 2.28.0 and later, or 2.27.4 on the 2.27.x branch.

Affected products

  • n8n n8n < 2.28.0, < 2.27.4 on 2.27.x branch

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory: Published as GHSA-h9fm-xcv2-qfw3 then withdrawn as duplicate of GHSA-33q9-f52j-gc75
  • 2026-07-08: patched: Patches released in n8n 2.28.0 and 2.27.4

References

Related threats