CVE-2026-85173Medium· 4.3▾ Sunlitn8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attac…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
— → 4.3
none → medium
n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
n8n < 2.35.4n8n >= 2.36.0, < 2.36.2Upgrade past the affected range:
n8n 2.36.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-72774Medium· 6.5n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node
CVE-2026-59259Mediumn8n: External Secrets Permission Bypass via Expression Parser Mismatch
CVE-2026-59254Mediumn8n: External Secrets Accessible via Workflow Expressions Outside Credentials
CVE-2026-59253Mediumn8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
GHSA-mwq7-vcmc-cm4qHighDuplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
CVE-2026-65016Highn8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner