CVE-2026-86996
Analyzed Analyzed - Analysis Complete

Authentication Bypass in n8n Workflow Automation

Vulnerability report for CVE-2026-86996, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted workflow and read its returned data. The affected path is packages/cli/src/modules/agents/tools/workflow-tool-factory.ts, where executeWorkflow omitted SubworkflowPolicyChecker.checkForProject. This issue is fixed in versions 2.37.7 and 2.38.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
n8n n8n to 2.37.7 (exc)
n8n n8n From 2.38.0 (inc) to 2.38.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in n8n allows users who can build an Agent to bypass workflow restrictions. Normally, workflows have a setting called 'This workflow can be called by' to limit who can execute them. However, when a workflow is attached to an Agent as a tool, this restriction was not enforced. This means an attacker could call restricted workflows and read their output data.

Impact Analysis

If you use n8n with Agents and workflows that have restricted access, an attacker with Agent-building permissions could access sensitive workflow data. This could lead to unauthorized data exposure, depending on what the restricted workflows process. The impact depends on the workflows' sensitivity and the data they handle.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements like GDPR (data protection) or HIPAA (health information). If restricted workflows process personal or health data, the breach could result in non-compliance, legal penalties, or reputational damage.

Mitigation Strategies
  • Upgrade n8n to version 2.37.7 or 2.38.2 or later to patch the vulnerability.
  • Restrict access to the n8n instance to trusted users only.
  • Audit workflows attached as Agent tools and remove sensitive workflows from Agent tool configurations until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86996. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart