VDB
CVE-2026-56350
CVE-2026-56350
PUBLISHED
CVSS 6 MEDIUM
Reported by VulnCheck · Published June 30, 2026
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
Risk Scores
CVSS 4.0
6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n8n | n8n | 0, 2.8.0 |
| n8n | n8n | 0, 2.8.0, 0 |
Timeline
- Jun 30, 2026 CVE Published
- Jul 1, 2026 EPSS Score
- Jul 1, 2026 Coalition ESS Score
- Jul 1, 2026 CVE Updated
References
- GitHub Security Advisory (GHSA-vjf3-2gpj-233v) vendor-advisory
- VulnCheck Advisory: n8n - SSO Enforcement Bypass via API third-party-advisory