CVE-2026-92588: n8n before 1.123.76 Improper Authorization via Source Control Push

Published Sep 16, 2026
·
Updated

n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of from the server-side status computed for the requesting user. An authenticated project-scoped user (e.g., a project admin) could therefore reference files belonging to projects they have no access to and push a deletion of those projects' workflows and credentials, resulting in cross-project data destruction. Exploitation requires the Source Control (Environments) enterprise feature to be licensed, enabled, and connected to a remote repository. The issue is fixed in 1.123.76, 2.37.7, and 2.38.2.

Affected Software

1 affected component
n8n n8n<1.123.76, =2.37.7, =2.38.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 1.123.76
  2. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.37.7
  3. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.38.2

Event History

Sep 16, 2026
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to exploitation?

Only deployments using the licensed Source Control (Environments) enterprise feature are exposed, and that feature must be enabled and connected to a remote repository. An affected n8n version alone is not sufficient.

2

What level of access does an attacker need?

An attacker must be authenticated as a project-scoped user, such as a project admin. They can exploit the issue by submitting client-supplied file paths and status that reference projects they are not authorized to access.

3

What is the practical impact?

The attacker can push deletions of workflows and credentials belonging to other projects. The described impact is cross-project data destruction; no confidentiality or availability impact is stated.

4

Which versions remediate the issue?

Upgrade to n8n 1.123.76, 2.37.7, or 2.38.2, as appropriate for the deployed release line. Versions before those releases are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203