CVE-2026-85173
⚪ Do wiadomości
Brak autoryzacji w n8n pozwala uwierzytelnionym użytkownikom na dostęp do danych projektów.
CVSS
4.3
EPSS
0.3%
Exploit
none
Vendor
n8n
Opis źródłowy (NVD)
n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-09-03 13:06:24 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-16 21:21:54 UTC |
Referencje
- https://github.com/n8n-io/n8n/security/advisories/GHSA-jmmj-93rg-6j39 ([email protected]) [Mitigation, Vendor Advisory]
- https://www.vulncheck.com/advisories/n8n-before-2.36.2-missing-authorization-via-insights-api ([email protected]) [Third Party Advisory]