Privilege Escalation Vulnerability in n8n by n8n.io
CVE-2026-65015

7.2HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-65015?

The n8n platform before version 2.30.1 features a security flaw within the AI Agents capability, where insufficient authorization checks allow a Project Viewer user to escalate their privileges. By interacting with an agent that has node tools enabled, users can run arbitrary nodes and access sensitive credential secrets, without the necessary authorization verifications in place. This can result in unauthorized access to critical information and system capabilities.

Affected Version(s)

n8n 0 < 2.30.1

n8n 0 < 2.29.8

n8n 2.30.1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

trap-bytes
.