NCSC-2026-0228 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platform
n8n has fixed multiple vulnerabilities in the n8n workflow automation platform. The vulnerabilities include: - An authorization issue where authenticated users can assign workflows to folders within projects they do not have access to, due to insufficient validation of request payloads during workflow creation. - A SQL injection in the legacy MySQL v1 node executeQuery operation due to unparameterized expression substitution, allowing the execution of arbitrary SQL statements. - Furthermore, authenticated users with the workflow:create permission can cause Object.prototype pollution via specially crafted workflows, leading to unauthorized access to privileged endpoints. - Another vulnerability involves bypassing HTTP request domain restrictions in the AI Agents functionality by users with member-level permissions, which may result in exposure of shared credential secrets to external servers. - There is also an issue with improper validation of multiple trusted token-exchange issuers, allowing impersonation of users across different token issuers. - Finally, users with editor access can exfiltrate sensitive credential data via HTTP Request node pagination expressions. These vulnerabilities are present in various versions of n8n and relate to authorization, authentication, data integrity, and confidentiality within the platform.
CSIRTS triage
- What
- There are multiple vulnerabilities including authorization issues and SQL injection.
- Who is affected
- Authenticated users of the n8n workflow automation platform are affected.
- Urgency
- Remediation is urgent due to the potential for unauthorized access and data manipulation.
- Action
- Update to the latest version of n8n to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0228
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-592530.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-592570.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-592060.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-592070.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-592080.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-592090.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59253 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59257 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59206 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59207 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59208 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59209 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumGHSA-2xgm-wc4g-5jvg: n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in …ghsa
- mediumGHSA-hwmj-qg4v-cvg9: n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expres…ghsa
- highGHSA-mq3m-f8x3-579w: n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolutionghsa
- highGHSA-h44j-f5r5-ph73: n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connectorghsa
- highGHSA-75qm-gp28-rcq9: n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Proje…ghsa
- highGHSA-q3j5-8vrg-4p9q: n8n: Shared Credential Header Leak via HTTP Request Pagination Expressionghsa
- high[UPDATE] [high] n8n: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-59209: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an…nvd
- mediumCVE-2026-59208: n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2…nvd
- mediumCVE-2026-59207: n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents …nvd
- highCVE-2026-59206: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an…nvd
- highCVE-2026-59257: n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vuln…nvd
Recent advisories for n8n workflow automation
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0248 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platformncsc-nl · 2026-07-17
- mediumCVE-2026-59209: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an…nvd · 2026-07-09
- mediumCVE-2026-59208: n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2…nvd · 2026-07-09
- mediumCVE-2026-59207: n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents …nvd · 2026-07-09
- highCVE-2026-59206: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an…nvd · 2026-07-09
- unknownNCSC-2026-0212 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platformncsc-nl · 2026-06-29
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30