CVE-2026-56350: n8n - SSO Enforcement Bypass via API
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56350?
The severity of CVE-2026-56350 is medium, rated at 6.
How do I fix CVE-2026-56350?
To fix CVE-2026-56350, update n8n to version 2.8.0 or later.
What type of vulnerability is CVE-2026-56350?
CVE-2026-56350 is an authentication bypass vulnerability.
Who is affected by CVE-2026-56350?
CVE-2026-56350 affects users of n8n prior to version 2.8.0 who utilize SSO.
What are the potential implications of CVE-2026-56350?
The potential implications of CVE-2026-56350 include unauthorized access to systems by bypassing organizational SSO policies.