CVE-2026-56350 Details
Description
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
A vulnerability exists in n8n versions prior to 2.8.0, allowing authenticated users who log in via Single Sign-On (SSO) to bypass SSO enforcement through the n8n API. This vulnerability enables users to disable SSO requirements for their accounts, create local password credentials, and authenticate directly, thereby circumventing organizational SSO policies and any multi-factor authentication mandated by identity providers.
Users should upgrade to n8n version 2.8.0 or later. If an immediate upgrade is not possible, administrators can monitor audit logs for the creation of local credentials after SSO authentication and restrict access to the n8n instance to fully trusted users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-vjf3-2gpj-233v | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/n8n-sso-enforcement-bypass-via-api | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 2.8.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |