CVE-2026-86085
Analyzed Analyzed - Analysis Complete

Role Assignment Information Disclosure in n8n

Vulnerability report for CVE-2026-86085, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: GitHub, Inc.

Description

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A caller with role:manageProject could name a project the caller could not list and obtain member names and email addresses. The affected controller is packages/cli/src/controllers/role.controller.ts, which omitted the project:list scope check. This issue is fixed in versions 2.37.7 and 2.38.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
n8n n8n to 2.37.7 (exc)
n8n n8n From 2.38.0 (inc) to 2.38.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in n8n versions before 2.37.7 and 2.38.2 allows a user with role:manageProject privileges to access member names and email addresses of projects they cannot list. This occurs because the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints only verify role management permissions without checking project:list scope.

Impact Analysis

An attacker with role:manageProject access could enumerate project members and obtain their email addresses, potentially leading to privacy breaches or targeted phishing attacks. This exposes sensitive user information without requiring additional permissions.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data without consent and HIPAA by disclosing protected health information. It undermines data minimization and access control requirements in these regulations.

Mitigation Strategies

Upgrade n8n to version 2.37.7, 2.38.2, or later to address the missing project:list scope check in the role assignment endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86085. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart