Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

n8n privilege escalation and OAuth authorization vulnerabilities

n8n versions before 2.30.1 contain two critical vulnerabilities in AI Agents and OAuth 2.1 features that allow users to escalate privileges, execute arbitrary nodes, access credential secrets, and bypass workflow authorization checks.

Disclosed 22 July 2026 · Record updated 13 September 2026

Impact

Project Viewer users can escalate privileges through AI Agents to execute arbitrary nodes and access credentials; member-level users can bypass OAuth authorization to access other users' workflows and credentials.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65015
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65594