CVE-2026-85173

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

16 Sep 2026, 21:21

Type Values Removed Values Added
First Time N8n
N8n n8n
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-jmmj-93rg-6j39 - () https://github.com/n8n-io/n8n/security/advisories/GHSA-jmmj-93rg-6j39 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/n8n-before-2.36.2-missing-authorization-via-insights-api - () https://www.vulncheck.com/advisories/n8n-before-2.36.2-missing-authorization-via-insights-api - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

Information

Published : 2026-09-03 13:06

Updated : 2026-09-16 21:21


NVD link : CVE-2026-85173

Mitre link : CVE-2026-85173

CVE.ORG link : CVE-2026-85173


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-639

Authorization Bypass Through User-Controlled Key