CVE-2026-65594: n8n before 2.30.1 Missing OAuth Authorization Check
Impact The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level user can register an OAuth client, self-approve consent for another user's n8n OAuth2-protected MCP Server Trigger workflow, and obtain a valid token for it.
The workflow runs in the owner's project context with the owner's stored credentials. The attacker sets the tool inputs and reads the outputs, which may include data from the owner's connected integrations, breaking user and project isolation. The resulting executions appear under the owner's account and are not visible to the attacker.
This issue only affects instances running n8n 2.27.0 or later where at least one active workflow uses an MCP Server Trigger node configured with n8n OAuth2 authentication.
Patches The issue has been fixed in n8n versions 2.29.8 and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability.
Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Audit active workflows using the MCP Server Trigger with n8n OAuth2 authentication and consider switching to a different authentication method or deactivating them until the patch is applied.
These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Other sources
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client, self-approve consent for another user's workflow, and obtain a valid token. The workflow then runs in the owner's project context with the owner's stored credentials, and the attacker can set tool inputs and read outputs (potentially including data from the owner's connected integrations), breaking user and project isolation.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/n8nto a version that resolves this vulnerability.Fixed in 2.29.8 - Upgrade
Upgrade
npm/n8nto a version that resolves this vulnerability.Fixed in 2.30.1 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.29.8 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.30.1 - Configuration
Audit active workflows using the MCP Server Trigger with `n8n OAuth2` authentication and consider switching to a different authentication method or deactivating them until the patch is applied.
n8n MCP Server Trigger workflow authentication method = (switch away from n8n OAuth2) or deactivate affected workflows - Compensating control
Restrict n8n instance access to fully trusted users only.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65594?
CVE-2026-65594 has a medium severity rating of 5.1 according to the CVSS score.
What is the impact of CVE-2026-65594?
The vulnerability allows unauthenticated users to access protected workflows by exploiting missing OAuth authorization checks.
How do I fix CVE-2026-65594?
To fix CVE-2026-65594, update n8n to version 2.30.1 or later, which includes the necessary OAuth authorization checks.
Who is affected by CVE-2026-65594?
Users of n8n prior to version 2.30.1 are affected by CVE-2026-65594.
What type of vulnerability is CVE-2026-65594?
CVE-2026-65594 is classified as an OAuth authorization vulnerability within n8n.