CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0228 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platform

unknownCVE-2026-59253CVE-2026-59257CVE-2026-59206CVE-2026-59207CVE-2026-59208CVE-2026-59209
n8n has fixed multiple vulnerabilities in the n8n workflow automation platform. The vulnerabilities include: - An authorization issue where authenticated users can assign workflows to folders within projects they do not have access to, due to insufficient validation of request payloads during workflow creation. - A SQL injection in the legacy MySQL v1 node executeQuery operation due to unparameterized expression substitution, allowing the execution of arbitrary SQL statements. - Furthermore, authenticated users with the workflow:create permission can cause Object.prototype pollution via specially crafted workflows, leading to unauthorized access to privileged endpoints. - Another vulnerability involves bypassing HTTP request domain restrictions in the AI Agents functionality by users with member-level permissions, which may result in exposure of shared credential secrets to external servers. - There is also an issue with improper validation of multiple trusted token-exchange issuers, allowing impersonation of users across different token issuers. - Finally, users with editor access can exfiltrate sensitive credential data via HTTP Request node pagination expressions. These vulnerabilities are present in various versions of n8n and relate to authorization, authentication, data integrity, and confidentiality within the platform.

CSIRTS triage

What
There are multiple vulnerabilities including authorization issues and SQL injection.
Who is affected
Authenticated users of the n8n workflow automation platform are affected.
Urgency
Remediation is urgent due to the potential for unauthorized access and data manipulation.
Action
Update to the latest version of n8n to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch n8n

Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-13
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0228

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-59253coverage & exploitation statusNVD · CVE.org
CVE-2026-59257coverage & exploitation statusNVD · CVE.org
CVE-2026-59206coverage & exploitation statusNVD · CVE.org
CVE-2026-59207coverage & exploitation statusNVD · CVE.org
CVE-2026-59208coverage & exploitation statusNVD · CVE.org
CVE-2026-59209coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for n8n workflow automation

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories