CVE-2026-56775 Details
Description
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:execute scope. On instances using Advanced Permissions (Enterprise/Cloud) with projects and viewer roles, an authenticated user with the project:viewer role can start new evaluation test runs, cancel in-flight runs, and delete run records for workflows they only have read access to.
A vulnerability exists in n8n versions prior to 1.123.55, 2.25.7, and 2.26.2, allowing unauthorized state-changing actions through three mutating evaluation test-run endpoints. The issue arises because these endpoints incorrectly authorize actions using the 'workflow:read' scope instead of the appropriate 'workflow:execute' scope. This vulnerability affects instances with Advanced Permissions (Enterprise/Cloud) that utilize projects and viewer roles. An authenticated user with the project:viewer role can initiate new evaluation test runs, cancel ongoing runs, and delete run records for workflows that are only accessible in a read-only capacity.
Users should upgrade to n8n versions 1.123.55, 2.25.7, or 2.26.2. If an immediate upgrade is not possible, consider restricting project membership to trusted users and avoiding viewer access to sensitive workflows.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-664h-gpgq-h6xx | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/n8n-incorrect-oauth-scope-validation-in-evaluation-test-runs-endpoints | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 1.123.55 >= 2.0.0, < 2.25.7 >= 2.26.0, < 2.26.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |