Authorization Bypass in n8n Project Role Deletion by n8n
CVE-2026-77079
7.4HIGH
What is CVE-2026-77079?
The n8n automation tool prior to versions 2.34.1 and 2.33.4 is vulnerable to an authorization bypass in its custom project role deletion process. The vulnerability allows a user with minimal permissions (manageProject global scope) to delete custom project roles without proper project-level authorization checks. This oversight permits them to reassign the roles, including their own, to the built-in project:admin role, thereby obtaining elevated privileges and inappropriate access to project resources that should be restricted.
Affected Version(s)
n8n 2.34.0 < 2.34.1
n8n 2.0.0 < 2.33.4
n8n 2.34.1
