GHSA-h9fm-xcv2-qfw3Medium▾ SunlitDuplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-33q9-f52j-gc75. This link is maintained to preserve external references.
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration. The impact is limited to disrupting in-progress test sessions; production webhooks, persistent workflow state, and stored data are not affected.
n8n < 2.27.4Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65014Mediumn8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
CVE-2026-54309High· 10.0n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform
CVE-2026-86085Medium· 4.9n8n is an open source workflow automation platform
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform