n8n privilege escalation and OAuth authorization vulnerabilities
n8n versions before 2.30.1 contain two critical vulnerabilities in AI Agents and OAuth 2.1 features that allow users to escalate privileges, execute arbitrary nodes, access credential secrets, and bypass workflow authorization checks.
Disclosed 22 July 2026 · Record updated 13 September 2026
Impact
Project Viewer users can escalate privileges through AI Agents to execute arbitrary nodes and access credentials; member-level users can bypass OAuth authorization to access other users' workflows and credentials.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65015
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65594
