CVE-2026-59206: n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
Impact An authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via the workflow API. This can be leveraged to bypass authentication, allowing unauthenticated requests to be treated as a privileged user and exposing endpoints such as the user and project listings. As a result, every account's personal data (email, role, MFA status) and all projects on the instance may be disclosed to unauthenticated callers. The pollution can also corrupt global state, making parts of the instance unresponsive until restarted.
Patches The issue has been fixed in n8n versions 1.123.61, 2.27.4, and 2.28.1. Users should upgrade to one of these versions or later to remediate the vulnerability.
Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict workflow creation and editing permissions to fully trusted users only. - Restrict network access to the n8n instance to trusted users only.
These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Other sources
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via the workflow API, allowing unauthenticated requests to be treated as a privileged user and exposing user and project listing endpoints. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/n8nto a version that resolves this vulnerability.Fixed in 2.27.4 - Upgrade
Upgrade
npm/n8nto a version that resolves this vulnerability.Fixed in 2.28.1 - Upgrade
Upgrade
npm/n8nto a version that resolves this vulnerability.Fixed in 1.123.61 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 1.123.61 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.27.4 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.28.1 - Compensating control
Restrict network access to the n8n instance to trusted users only (short-term mitigation if upgrading is not immediately possible).
- Compensating control
Restrict workflow creation and editing permissions to fully trusted users only (short-term mitigation if upgrading is not immediately possible).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59206?
The severity of CVE-2026-59206 is rated at 56.
How do I fix CVE-2026-59206?
To mitigate CVE-2026-59206, upgrade n8n to versions 1.123.61, 2.27.4, or 2.28.1.
What impact does CVE-2026-59206 have on n8n users?
CVE-2026-59206 allows authenticated users to exploit prototype pollution, leading to unauthenticated user and project enumeration.
Who is affected by CVE-2026-59206?
CVE-2026-59206 affects n8n installations prior to versions 1.123.61, 2.27.4, and 2.28.1.
How can I determine if my n8n installation is vulnerable to CVE-2026-59206?
Check your n8n version against the patched releases; if it is below 1.123.61, 2.27.4, or 2.28.1, your installation is vulnerable.