CVE-2026-86085Medium· 4.9▾ Sunlitn8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
4.9 → 5.1
5.1 → 4.9
4.9 → 5.1
5.1 → 4.9
4.9 → 5.1
5.1 → 4.9
4.9 → 5.1
5.1 → 4.9
4.9 → 5.1
5.1 → 4.9
4.9 → 5.1
5.1 → 4.9
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A caller with role:manageProject could name a project the caller could not list and obtain member names and email addresses. The affected controller is packages/cli/src/controllers/role.controller.ts, which omitted the project:list scope check. This issue is fixed in versions 2.37.7 and 2.38.2.
n8n < 2.37.7n8n >= 2.38.0, < 2.38.2Upgrade past the affected range:
n8n 2.38.2Affected packages:
n8n >= 2.38.0, < 2.38.2n8n < 2.37.7Patched in:
n8n 2.38.2n8n 2.37.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform
CVE-2026-86077Medium· 6.5n8n is an open source workflow automation platform
CVE-2026-86996Medium· 5.4n8n is an open source workflow automation platform
CVE-2026-86993Medium· 4.9n8n is an open source workflow automation platform
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform