Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77079— n8n before 2.34.1 Authorization Bypass via Custom Role Deletion

Quick assessment

Affected
n8n-io n8n
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 n8n 2.34.1 之前以及 2.33.4 版本中,自定义项目角色的删除(重新分配)路径存在授权绕过漏洞。当删除一个指定了重新分配目标的自定义项目角色时,代码仅验证了目标角色是否存在且属于项目范围,而未进行项目级别的授权检查。持有“角色:manageProject”全局权限范围(范围较窄)的用户,可以删除实例中正在使用的任何自定义项目角色,并将其持有者(包括用户自身)重新分配到内置的“项目:admin”角色,从而获得对其原本无权访问的项目的完全管理控制权。

CVSS 7.4 · High EPSS 0.23% · P13

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 4

VendorProduct Version RangeStatus
n8n-io n8n 2.34.0< 2.34.1 affected
2.34.1 unaffected
2.0.0< 2.33.4 affected
2.33.4 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77079

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
n8n before 2.34.1 Authorization Bypass via Custom Role Deletion
Source: CVE Program / CVE List V5
Vulnerability Description
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) to the built-in project:admin role, gaining full administrative control of projects they had no legitimate access to.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
n8n-io n8n 2.34.0 ~ 2.34.1 -
n8n-io n8n 2.0.0 ~ 2.33.4 -

II. Public POCs for CVE-2026-77079

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77079

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77079 (2)

Same Patch Batch · n8n-io · 2026-08-20 · 17 CVEs total

CVE-2026-77080 8.7 HIGH n8n before 1.123.69 Arbitrary File Read and Write via Snowflake
CVE-2026-77068 8.7 HIGH n8n before 2.34.1 Remote Code Execution via Path Traversal
CVE-2026-77075 8.4 HIGH n8n before 1.123.69 Expression Injection via Resource Locator
CVE-2026-77072 8.4 HIGH n8n before 1.123.69 Stored XSS via Form Completion Page
CVE-2026-77084 7.7 HIGH n8n before 1.123.69 Remote Code Execution via Git Node Configuration Values
CVE-2026-77077 7.2 HIGH n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution
CVE-2026-77071 7.1 HIGH n8n before 1.123.69 PostgREST Filter Injection via Supabase
CVE-2026-77076 7.1 HIGH n8n before 1.123.69 Credential Leak via GraphQL Node Error
CVE-2026-77070 7.1 HIGH n8n before 1.123.69 NoSQL Injection via MongoDB Node
CVE-2026-77085 6.3 MEDIUM n8n before 2.34.1 SSRF Protection Bypass via SearXNG Tool
CVE-2026-77083 6.0 MEDIUM n8n before 1.123.69 Code Node Sandbox Escape via Function.prototype Pollution
CVE-2026-77074 6.0 MEDIUM n8n before 1.123.69 SSRF via Edit Image Node
CVE-2026-77073 5.3 MEDIUM n8n before 2.34.1 Cross-Project Credential Access via MCP
CVE-2026-77082 5.3 MEDIUM n8n before 1.123.69 ReDoS via Filter and Switch Node
CVE-2026-77081 5.1 MEDIUM n8n before 1.123.69 Allowed-Domains Bypass via GraphQL Node
CVE-2026-77069 2.3 LOW n8n before 1.123.69 SSRF Protection Bypass via OAuth2

IV. Related Vulnerabilities

V. Comments for CVE-2026-77079

No comments yet


Leave a comment