Back to overview

CVE-2026-65015

HIGH
7.2
CVSS 4.0
Description
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.

Metadata

CVE ID
CVE-2026-65015
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-21 11:32 UTC
Published
2026-07-22 11:21 UTC
Last updated
2026-07-22 11:21 UTC
Primary CWE
CWE-863
Incorrect Authorization
Vendor / Product
n8n-io / n8n
Sources
cve.org  ·  NVD

Severity & Metrics

7.2 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L
Affected products (2)
VendorProductPlatformVersions
n8n-io n8n 0 < 2.30.1, 2.30.1
n8n-io n8n 0 < 2.29.8, 2.29.8
Weakness (CWE)
CWESourceDescription
CWE-863 cna Incorrect Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.2 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L
References (2)
Back to overview