CVE-2026-56776Disclosure(n8n / n8n)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only access to a workflow can trigger a real evaluation test run, causing the workflow to execute via the internal workflow runner and resulting in unintended outbound API calls, data mutations, or other side effects in connected downstream systems. The issue primarily affects instances using the Evaluations feature where RBAC project roles grant workflow:read without workflow:execute.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - n8n Evaluations test-run authorization bypass (CVE-2026-56776) n8n has an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint within the Evaluations feature, where execution is incorrectly permitted for users who only have workflow:read access. The root cause is improper authorization/scope enforcement (broken access control) that checks workflow:read instead of the required workflow:execute. An attacker only needs to be authenticated with a read-only RBAC role and access to a workflowId to trigger a real evaluation test run, leading to unintended execution without proper privileges. If exploited, this can cause unauthorized workflow actions including outbound API calls, data modification in connected systems, and potentially cascading business process abuse. 👉 Affected: n8n (instances using Evaluations with RBAC roles granting workflow:read without workflow:execute) | Upgrade to No fix yet — treat as suspicious

    Post summary

    The post announces an authorization bypass in n8n’s Evaluation feature that lets read‑only users trigger test runs, potentially causing unintended execution; no fix or exploit evidence is available yet.

    00000115
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more