CVE-2026-59206
n8n has fixed multiple vulnerabilities in the n8n workflow automation platform. The vulnerabilities include: - An authorization issue where authenticated users can assign workflows to folders within projects they do not have access to, due to insufficient validation of request payloads during workflow creation. - A SQL injection in the legacy MySQL v1 node executeQuery operation due to unparameterized expression substitution, allowing the execution of arbitrary SQL statements. - Furthermore, authenticated users with the workflow:create permission can cause Object.prototype pollution via specially crafted workflows, leading to unauthorized access to privileged endpoints. - Another vulnerability involves bypassing HTTP request domain restrictions in the AI Agents functionality by users with member-level permissions, which may result in exposure of shared credential secrets to external servers. - There is also an issue with improper validation of multiple trusted token-exchange issuers, allowing impersonation of users across different token issuers. - Finally, users with editor access can exfiltrate sensitive credential data via HTTP Request node pagination expressions. These vulnerabilities are present in various versions of n8n and relate to authorization, authentication, data integrity, and confidentiality within the platform.
CSIRTS triage
- What
- There are multiple vulnerabilities including authorization issues and SQL injection.
- Who is affected
- Authenticated users of the n8n workflow automation platform are affected.
- Urgency
- Remediation is urgent due to the potential for unauthorized access and data manipulation.
- Action
- Update to the latest version of n8n to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-59206
Get an email if CVE-2026-59206 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Advisory coverage (3)
- highGHSA-75qm-gp28-rcq9: n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Proje…ghsa · 2026-07-22
- unknownNCSC-2026-0228 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platformncsc-nl · 2026-07-13
- highCVE-2026-59206: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an…nvd · 2026-07-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-59206)