VDB

CVE-2026-56350

CVE-2026-56350 PUBLISHED CVSS 6 MEDIUM

Reported by VulnCheck · Published June 30, 2026

n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.

Risk Scores

CVSS 4.0
6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
n8nn8n0, 2.8.0
n8nn8n0, 2.8.0, 0

Timeline

  • Jun 30, 2026 CVE Published
  • Jul 1, 2026 EPSS Score
  • Jul 1, 2026 Coalition ESS Score
  • Jul 1, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›