CVE-2026-59253

MEDIUM

n8n - Improper Authorization in Workflow Assignment to Folders

Title source: cna
STIX 2.1

Description

n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request payloads during workflow creation, causing logical integrity violations in target project folder structures.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-2xgm-wc4g-5jvg)
https://github.com/n8n-io/n8n/security/advisories/GHSA-2xgm-wc4g-5jvg
Third Party Advisory third-party-advisory
VulnCheck Advisory: n8n - Improper Authorization in Workflow Assignment to Folders
https://www.vulncheck.com/advisories/n8n-improper-authorization-in-workflow-assignment-to-folders

Scores

CVSS v3 5.0
EPSS 0.0017
EPSS Percentile 6.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (3)
n8n/n8n < 2.28.0 (2 CPE variants)
n8n/n8n 2.28.0
npm/n8n 0 - 2.28.0npm
Published Jul 08, 2026
Tracked Since Jul 08, 2026