n8n Authorization Vulnerability in Evaluation Test-Run Endpoints Allowing Unauthorized Workflow Execution

Vulnerability

A vulnerability exists in n8n versions prior to 1.123.55, 2.25.7, and 2.26.2, allowing unauthorized state-changing actions through three mutating evaluation test-run endpoints. The issue arises because these endpoints incorrectly authorize actions using the 'workflow:read' scope instead of the appropriate 'workflow:execute' scope. This vulnerability affects instances with Advanced Permissions (Enterprise/Cloud) that utilize projects and viewer roles. An authenticated user with the project:viewer role can initiate new evaluation test runs, cancel ongoing runs, and delete run records for workflows that are only accessible in a read-only capacity.

Impact

Exploitation of this vulnerability allows an authenticated user with the project:viewer role to perform unauthorized actions on workflows, including starting and managing evaluation test runs and deleting run records, for workflows they only have read access to.

Remediation

Users should upgrade to n8n versions 1.123.55, 2.25.7, or 2.26.2. If an immediate upgrade is not possible, consider restricting project membership to trusted users and avoiding viewer access to sensitive workflows.

Added: Jul 8, 2026, 2:30 PM
Updated: Jul 8, 2026, 2:30 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
4.9
remediation
7.9
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.