Privilege Escalation Vulnerability in n8n by n8n-io
CVE-2026-65016
7.7HIGH
What is CVE-2026-65016?
In n8n versions prior to 1.123.64, 2.29.8, and 2.30.1, a privilege escalation vulnerability exists in the Enterprise SSO instance-role provisioning mechanism. This flaw allows an attacker, who manages to control the instance-role claim issued by the Identity Provider (IdP), to be bestowed with the global:owner role without appropriate checks. Consequently, this unauthorized access can result in full administrative control over critical assets including workflows, credentials, and user configurations. This vulnerability necessitates specific conditions to be exploited, notably configuration of Enterprise SSO and enabling instance-role provisioning.
Affected Version(s)
n8n 0 < 1.123.64
n8n 0 < 2.30.1
n8n 0 < 2.29.8
