Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and later disabled an identity provider still exposed a working route that could issue valid sessions. The affected logic is packages/cli/src/modules/sso-oidc/oidc.service.ee.ts, including generateLoginUrl and the callback flow that lacked assertOidcLoginEnabled. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

Prior to the application of specific releases, the public OIDC login and callback endpoints in n8n could complete authentication even when OIDC was not the active method. This flaw allowed an attacker to use a formerly enabled identity provider that had been disabled by an administrator to generate valid, authenticated sessions. The vulnerability is an authentication bypass that can lead to unauthorized access to the system, potentially compromising data confidentiality and integrity.

Affected Systems

This issue affects the n8n workflow automation platform produced by n8n‑io. All releases older than 1.123.76 for the 1.x series, older than 2.37.7 for the 2.37.x series, and older than 2.38.2 for the 2.38.x series are vulnerable. The bug resides in the OIDC service module within the enterprise edition. Administrators using these pre‑patch versions should review their deployment and ensure the vulnerable endpoints are not exposed.

Risk and Exploitability

The CVSS score of 6 indicates a medium severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The affected endpoints are publicly reachable, meaning that an external attacker can trigger the flow without prior privileges. Because the flaw accepts a valid OIDC flow even after administrative disabling, a malicious actor could hijack credentials and gain unauthorized session access. The risk is therefore moderate, but because the vulnerability is exploitable through standard HTTP requests, organizations should prioritize remediation.

Generated by OpenCVE AI on September 9, 2026 at 08:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the n8n installation to version 1.123.76 or later, or version 2.37.7 or 2.38.2 or newer, to apply the fix that disables the OIDC endpoints when disabled.
  • Verify that the OIDC authentication method is indeed disabled in the configuration and that the corresponding login and callback URLs are no longer reachable.
  • Audit authentication logs to confirm that no unexpected or unauthorized sessions were created after disabling OIDC, and invalidate any sessions that appear suspicious.

Generated by OpenCVE AI on September 9, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pf83-w3f9-8m37 n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}


Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and later disabled an identity provider still exposed a working route that could issue valid sessions. The affected logic is packages/cli/src/modules/sso-oidc/oidc.service.ee.ts, including generateLoginUrl and the callback flow that lacked assertOidcLoginEnabled. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:50:25.691Z

Reserved: 2026-09-04T19:34:03.101Z

Link: CVE-2026-86084

cve-icon Vulnrichment

Updated: 2026-09-09T13:50:11.260Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:17.527

Modified: 2026-09-10T21:10:42.127

Link: CVE-2026-86084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:15:17Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel