CVE-2026-86084
Analyzed Analyzed - Analysis Complete

Authentication Bypass in n8n via OIDC Endpoint

Vulnerability report for CVE-2026-86084, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and later disabled an identity provider still exposed a working route that could issue valid sessions. The affected logic is packages/cli/src/modules/sso-oidc/oidc.service.ee.ts, including generateLoginUrl and the callback flow that lacked assertOidcLoginEnabled. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
n8n n8n From 2.38.0 (inc) to 2.38.2 (exc)
n8n n8n to 1.123.76 (exc)
n8n n8n From 2.0.0 (inc) to 2.37.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in n8n allows disabled OIDC SSO endpoints to remain active and issue valid sessions. Even after OIDC authentication is turned off in settings, the public OIDC login and callback endpoints continue functioning, enabling unauthorized session creation. The issue affects Enterprise instances where OIDC was previously configured and later disabled.

Detection Guidance

Check if OIDC SSO endpoints are active despite being disabled in settings. Inspect network traffic for requests to /rest/oauth2-credential/login and /rest/oauth2-credential/callback. Verify n8n version is below 1.123.76, 2.37.7, or 2.38.2.

Impact Analysis

An attacker with network access could exploit this to create valid sessions without proper authentication, potentially gaining unauthorized access to n8n workflows or data. The attack requires low privileges and no user interaction but has high impact on confidentiality.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection standards like GDPR and HIPAA. Unauthorized session issuance may result in data breaches, triggering regulatory penalties and compliance violations.

Mitigation Strategies

Upgrade n8n to versions 1.123.76, 2.37.7, or 2.38.2 or later. Disable or revoke the OIDC application at the Identity Provider level. Restrict network access to trusted users only as a temporary measure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86084. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart