n8n: missing authorization
MediumCVE-2026-86085 · Published Sep 10, 2026
## Impact The endpoints `/rest/roles/:slug/assignments` and `/rest/roles/:slug/assignments/:projectId/members` checked only that the caller could manage the role type, not that they could see the project named in the request. A user holding role-management permission could therefore name any project on the instance and read back its members' names and email addresses. The patch adds a project-access check to both routes, hiding projects the caller cannot see and returning not-found for a project it cannot list. ## Patches The issue has been fixed in n8n versions 2.38.2 and 2.37.7. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Audit and revoke any custom global roles that carry the `role:manageProject` scope, limiting that scope to fully trusted users only. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| n8n npm | >= 2.38.0, < 2.38.2 | 2.38.2 |
| < 2.37.7 | 2.37.7 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-862
- Also known as
- CVE-2026-86085
More n8n advisories
All n8n| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution | Medium | 2.37.7+1 more |
| Sep 10 | n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content | Medium | 2.37.7+1 more |
| Sep 10 | n8n: path traversal | Medium | 1.123.76+2 more |
| Sep 10 | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check | Medium | 1.123.76+2 more |
| Sep 10 | n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions | Medium | 1.123.76+2 more |
| Sep 10 | n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open | Medium | 1.123.76+2 more |