Authorization Bypass in n8n Project Role Deletion by n8n
CVE-2026-77079

7.4HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77079?

The n8n automation tool prior to versions 2.34.1 and 2.33.4 is vulnerable to an authorization bypass in its custom project role deletion process. The vulnerability allows a user with minimal permissions (manageProject global scope) to delete custom project roles without proper project-level authorization checks. This oversight permits them to reassign the roles, including their own, to the built-in project:admin role, thereby obtaining elevated privileges and inappropriate access to project resources that should be restricted.

Affected Version(s)

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

n8n 2.34.1

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yadhukrishnam
.