Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4309 articles · 196687 vulns · 37/41 feeds (7d)
← Back to list
5.0
CVE-2026-59253PATCHED
n8n · n8n

n8n - Improper Authorization in Workflow Assignment to Folders

Description

n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request payloads during workflow creation, causing logical integrity violations in target project folder structures.

Affected Products

VendorProductVersions
n8nn8nnpm/n8n: < 2.28.0

References

  • https://github.com/n8n-io/n8n/security/advisories/GHSA-2xgm-wc4g-5jvg(vendor-advisory)
  • https://www.vulncheck.com/advisories/n8n-improper-authorization-in-workflow-assignment-to-folders(third-party-advisory)

Related News (1 articles)

Tier C
VulDB47d ago
CVE-2026-59253 | n8n up to 2.27.x Workflow Assignment improper authorization
→ No new info (linked only)
CVSS 3.15.0 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
n8n@2.28.0
CWECWE-639
PublishedJul 8, 2026
Last enriched47d agov2
Trending Score0
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-59259EXP
n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
MEDIUMCVE-2026-58661
n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
MEDIUMCVE-2026-59254EXP
n8n - External Secrets Disclosure via Workflow Node Expressions
NONECVE-2026-56354EXP
n8n - Cross-Site Scripting and Open Redirect in Form Node
NONECVE-2026-56360
n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 8, 2026
Discovered by ZDM
Jul 8, 2026
Patch Available
Jul 8, 2026
Updated: severity, affectedVersions
Jul 8, 2026

Version History

v2
Last enriched 47d ago
v2Tier C47d ago

Updated severity to CRITICAL, marked exploit availability as false, and specified affected versions as 2.27.x.

severityaffectedVersions
via VulDB
v147d ago

Initial creation