Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-56778— n8n - Authorization Bypass in Public API Execution Retry Endpoint

CVSS 6.4 · Medium EPSS 0.17% · P7

Affected Version Matrix 4

VendorProductVersion RangeStatus
n8nn8n< 2.26.2affected
2.26.2unaffected
< 2.25.7affected
2.25.7unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-56778

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
n8n - Authorization Bypass in Public API Execution Retry Endpoint
Source: NVD (National Vulnerability Database)
Vulnerability Description
n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only access to a shared workflow can use the Public API to retry executions of that workflow, bypassing the intended permission boundary between read and execute access. This affects instances where workflows are shared with other users or across projects.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不正确
Source: NVD (National Vulnerability Database)
Vulnerability Title
n8n 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 2.25.7之前版本和2.26.2之前版本存在授权问题漏洞,该漏洞源于Public API execution retry端点存在授权绕过问题,该端点使用workflow:read作用域替代workflow:execute作用域进行访问授权,可能导致已通过身份验证的用户绕过读取和执行访问之间的预期权限边界。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
n8nn8n 0 ~ 2.26.2 -
n8nn8n 0 ~ 2.25.7 -

II. Public POCs for CVE-2026-56778

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56778

登录查看更多情报信息。

Vendor Advisories for CVE-2026-56778 (2)

Same Patch Batch · n8n · 2026-07-08 · 7 CVEs total

CVE-2026-567767.4 HIGHn8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint
CVE-2026-563595.4 MEDIUMn8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL
CVE-2026-567755.4 MEDIUMn8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints
CVE-2026-563604.0 MEDIUMn8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger
CVE-2026-59253n8n - Improper Authorization in Workflow Assignment to Folders
CVE-2026-59257n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation

IV. Related Vulnerabilities

V. Comments for CVE-2026-56778

No comments yet


Leave a comment