OAuth 2.1 Workflow Access Issue in n8n by n8n IO
CVE-2026-65594

5.1MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-65594?

An access control vulnerability in n8n allows authenticated users to exploit OAuth 2.1 protocols. If configured with an active MCP Server Trigger workflow, a user can register an OAuth client and approve access to another user's workflows. This can lead to unauthorized access to sensitive data and break project isolation, as actions taken will occur in the context of the workflow owner, using their stored credentials.

Affected Version(s)

n8n 0 < 2.30.1

n8n 0 < 2.29.8

n8n 2.30.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.