n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-vjf3-2gpj-233v | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-sso-enforcement-bypass-via-api | Third Party Advisory |
Configurations
History
02 Jul 2026, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-vjf3-2gpj-233v - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-sso-enforcement-bypass-via-api - Third Party Advisory | |
| First Time |
N8n
N8n n8n |
30 Jun 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 23:17
Updated : 2026-07-02 19:38
NVD link : CVE-2026-56350
Mitre link : CVE-2026-56350
CVE.ORG link : CVE-2026-56350
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-285
Improper Authorization
