Missing Per-Project Authorization Vulnerability in n8n Software
CVE-2026-85173

5.3MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85173?

n8n versions prior to 2.36.2 are susceptible to a missing per-project authorization issue in their Insights API routes. This vulnerability allows authenticated users granted insights scopes to exploit the system by supplying arbitrary projectId parameters, thereby gaining access to workflow names and execution statistics from projects in which they lack membership. Consequently, this opens the door for potential unauthorized access to sensitive project and workflow information, raising significant security concerns.

Affected Version(s)

n8n 0 < 2.36.2

n8n 0 < 2.35.4

n8n 2.36.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nlgbao1340
.