CVE-2026-65596
Analyzed Analyzed - Analysis Complete

Authentication Bypass in n8n Workflow Credentials

Vulnerability report for CVE-2026-65596, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-27

Assigner: VulnCheck

Description

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owner users are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-27
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
n8n n8n to 1.123.64 (exc)
n8n n8n From 2.0.0 (inc) to 2.29.8 (exc)
n8n n8n to 1.123.64 (exc)
n8n n8n From 2.0.0 (inc) to 2.29.8 (exc)
n8n n8n 2.30.0
n8n n8n 2.30.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects n8n versions before 1.123.64, 2.29.8, and 2.30.1. It allows authenticated users who can create or edit workflows to bypass the 'Allowed HTTP Request Domains' restriction on HTTP-based credentials in the GraphQL node. This enables them to send restricted credentials to a server they control.

Detection Guidance

Check n8n version with: n8n version. If version is below 1.123.64, 2.29.8, or 2.30.1, the system is vulnerable. Review workflows using GraphQL nodes with HTTP-based credentials to see if they point to external domains.

Impact Analysis

An attacker with workflow editing permissions could exfiltrate sensitive credentials like OAuth tokens or API keys. This could lead to unauthorized access to systems, data breaches, or further attacks using the stolen credentials.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, potentially violating GDPR or HIPAA compliance. Organizations using affected n8n versions may face regulatory penalties or reputational damage if credentials are exfiltrated.

Mitigation Strategies

Upgrade n8n to versions 1.123.64, 2.29.8, or 2.30.1 or later. Restrict workflow editing and credential sharing to trusted users only. Audit existing workflows for unauthorized domain changes in GraphQL nodes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65596. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart