CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59206

highCVSS 7.1covered by 3 sourcesfirst seen 2026-07-09
n8n has fixed multiple vulnerabilities in the n8n workflow automation platform. The vulnerabilities include: - An authorization issue where authenticated users can assign workflows to folders within projects they do not have access to, due to insufficient validation of request payloads during workflow creation. - A SQL injection in the legacy MySQL v1 node executeQuery operation due to unparameterized expression substitution, allowing the execution of arbitrary SQL statements. - Furthermore, authenticated users with the workflow:create permission can cause Object.prototype pollution via specially crafted workflows, leading to unauthorized access to privileged endpoints. - Another vulnerability involves bypassing HTTP request domain restrictions in the AI Agents functionality by users with member-level permissions, which may result in exposure of shared credential secrets to external servers. - There is also an issue with improper validation of multiple trusted token-exchange issuers, allowing impersonation of users across different token issuers. - Finally, users with editor access can exfiltrate sensitive credential data via HTTP Request node pagination expressions. These vulnerabilities are present in various versions of n8n and relate to authorization, authentication, data integrity, and confidentiality within the platform.

CSIRTS triage

What
There are multiple vulnerabilities including authorization issues and SQL injection.
Who is affected
Authenticated users of the n8n workflow automation platform are affected.
Urgency
Remediation is urgent due to the potential for unauthorized access and data manipulation.
Action
Update to the latest version of n8n to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-59206

Get an email if CVE-2026-59206 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-59206

CVE.org record

Embed the live status

CVE-2026-59206 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59206 status](https://www.csirts.com/badge/CVE-2026-59206)](https://www.csirts.com/cve/CVE-2026-59206)