Aller au contenu

Fiche vulnérabilité

CVE-2026-65015 : faille élevée n8n n8n (CVSS 8.8)

Description

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
22 juil. 2026
Dernière mise à jour
28 juil. 2026

Produits concernés

  • n8n n8n

Références

Rechercher une autre vulnérabilité dans la base CVE