Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can submit resume requests without verification of the requester's identity or approval permissions, allowing unauthenticated users to advance waiting executions and trigger guarded actions.
Published: 2026-10-01
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized execution of guarded actions via approval bypass
Action: Apply Patch
AI Analysis

Impact

A flaw in the Send and Wait node allows an attacker to submit resume requests in Approve Within Chat mode without properly verifying the requester’s identity or approval rights. This bypass lets an unauthenticated user advance waiting executions and trigger actions that are normally protected by approval gates, compromising the integrity of workflow automation. The weakness is a direct failure of authorization checks.

Affected Systems

The vulnerability exists in n8n-io’s n8n product for all releases prior to versions 2.39.6 and 2.40.0 before 2.40.1. Users running these affected builds are at risk.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw resides in a node that can be configured within a workflow, the likely attack path involves an attacker gaining access to the node’s configuration or interacting with the chat mode, which may require local or internal access. The lack of direct publicly disclosed exploitation evidence reduces immediate risk, though the permission skip is severe enough to warrant mitigation.

Generated by OpenCVE AI on October 1, 2026 at 14:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to n8n version 2.39.6 or later, or at least to 2.40.1 which contains the fix
  • Restrict access to the Send and Wait node and its chat mode to authenticated users only, applying appropriate network segmentation or ACLs
  • Review all existing workflows to ensure that the Approve Within Chat mode is disabled where approval is unnecessary, or replace them with alternative approval mechanisms

Generated by OpenCVE AI on October 1, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can submit resume requests without verification of the requester's identity or approval permissions, allowing unauthenticated users to advance waiting executions and trigger guarded actions.
Title n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node
First Time appeared N8n
N8n n8n
Weaknesses CWE-862
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:29:08.497Z

Reserved: 2026-09-30T10:55:39.869Z

Link: CVE-2026-103260

cve-icon Vulnrichment

Updated: 2026-10-01T13:28:46.331Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:20.660

Modified: 2026-10-01T14:17:22.310

Link: CVE-2026-103260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses