Privilege Escalation Vulnerability in n8n by n8n-io
CVE-2026-65016

7.7HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-65016?

In n8n versions prior to 1.123.64, 2.29.8, and 2.30.1, a privilege escalation vulnerability exists in the Enterprise SSO instance-role provisioning mechanism. This flaw allows an attacker, who manages to control the instance-role claim issued by the Identity Provider (IdP), to be bestowed with the global:owner role without appropriate checks. Consequently, this unauthorized access can result in full administrative control over critical assets including workflows, credentials, and user configurations. This vulnerability necessitates specific conditions to be exploited, notably configuration of Enterprise SSO and enabling instance-role provisioning.

Affected Version(s)

n8n 0 < 1.123.64

n8n 0 < 2.30.1

n8n 0 < 2.29.8

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ttzero25
.