
🚨 HIGH - n8n Evaluations test-run authorization bypass (CVE-2026-56776) n8n has an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint within the Evaluations feature, where execution is incorrectly permitted for users who only have workflow:read access. The root cause is improper authorization/scope enforcement (broken access control) that checks workflow:read instead of the required workflow:execute. An attacker only needs to be authenticated with a read-only RBAC role and access to a workflowId to trigger a real evaluation test run, leading to unintended execution without proper privileges. If exploited, this can cause unauthorized workflow actions including outbound API calls, data modification in connected systems, and potentially cascading business process abuse. 👉 Affected: n8n (instances using Evaluations with RBAC roles granting workflow:read without workflow:execute) | Upgrade to No fix yet — treat as suspicious
Post summary
The post announces an authorization bypass in n8n’s Evaluation feature that lets read‑only users trigger test runs, potentially causing unintended execution; no fix or exploit evidence is available yet.
