Missing Per-Project Authorization Vulnerability in n8n Software
CVE-2026-85173
5.3MEDIUM
What is CVE-2026-85173?
n8n versions prior to 2.36.2 are susceptible to a missing per-project authorization issue in their Insights API routes. This vulnerability allows authenticated users granted insights scopes to exploit the system by supplying arbitrary projectId parameters, thereby gaining access to workflow names and execution statistics from projects in which they lack membership. Consequently, this opens the door for potential unauthorized access to sensitive project and workflow information, raising significant security concerns.
Affected Version(s)
n8n 0 < 2.36.2
n8n 0 < 2.35.4
n8n 2.36.2
