CVE-2026-86994: CWE-862: Missing Authorization in n8n-io n8n
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, and publication push events were also broadcast to clients that could not access the affected workflow, disclosing workflow IDs, version IDs, and activation error details. The affected paths include packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
AI Analysis
Technical Summary
CVE-2026-86994 describes a missing authorization (CWE-862) vulnerability in the n8n open source workflow automation platform. Before versions 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned all active workflow IDs to any member without proper access control. Furthermore, workflow state change events were broadcast to clients lacking access rights, exposing workflow IDs, version IDs, and error details. The affected code paths are in packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. The vulnerability is resolved in the stated fixed versions.
Potential Impact
Unauthorized users can obtain identifiers of all active workflows on an instance, including those they should not access. They also receive broadcasted events revealing workflow IDs, version IDs, and activation error details. This information disclosure could aid attackers in reconnaissance or further attacks but does not directly allow workflow modification or execution.
Mitigation Recommendations
Upgrade n8n to version 1.123.76, 2.37.7, or 2.38.2 or later to apply the official fix. No other mitigation or temporary workaround is indicated. Patch status is not explicitly stated but the issue is fixed in these versions.
CVE-2026-86994: CWE-862: Missing Authorization in n8n-io n8n
Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, and publication push events were also broadcast to clients that could not access the affected workflow, disclosing workflow IDs, version IDs, and activation error details. The affected paths include packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/n8n-io/n8nRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86994 describes a missing authorization (CWE-862) vulnerability in the n8n open source workflow automation platform. Before versions 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned all active workflow IDs to any member without proper access control. Furthermore, workflow state change events were broadcast to clients lacking access rights, exposing workflow IDs, version IDs, and error details. The affected code paths are in packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. The vulnerability is resolved in the stated fixed versions.
Potential Impact
Unauthorized users can obtain identifiers of all active workflows on an instance, including those they should not access. They also receive broadcasted events revealing workflow IDs, version IDs, and activation error details. This information disclosure could aid attackers in reconnaissance or further attacks but does not directly allow workflow modification or execution.
Mitigation Recommendations
Upgrade n8n to version 1.123.76, 2.37.7, or 2.38.2 or later to apply the official fix. No other mitigation or temporary workaround is indicated. Patch status is not explicitly stated but the issue is fixed in these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-08T16:44:23.781Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa13d6bacd9273b49346a84
Added to database: 09/09/2026, 11:05:15 UTC
Last enriched: 09/09/2026, 11:09:32 UTC
Last updated: 09/10/2026, 01:57:54 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.