n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-jmmj-93rg-6j39 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-before-2.36.2-missing-authorization-via-insights-api | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Sep 2026, 21:21
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
N8n
N8n n8n |
|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-jmmj-93rg-6j39 - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-before-2.36.2-missing-authorization-via-insights-api - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* |
Information
Published : 2026-09-03 13:06
Updated : 2026-09-16 21:21
NVD link : CVE-2026-85173
Mitre link : CVE-2026-85173
CVE.ORG link : CVE-2026-85173
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
