Impact
Prior to the application of specific releases, the public OIDC login and callback endpoints in n8n could complete authentication even when OIDC was not the active method. This flaw allowed an attacker to use a formerly enabled identity provider that had been disabled by an administrator to generate valid, authenticated sessions. The vulnerability is an authentication bypass that can lead to unauthorized access to the system, potentially compromising data confidentiality and integrity.
Affected Systems
This issue affects the n8n workflow automation platform produced by n8n‑io. All releases older than 1.123.76 for the 1.x series, older than 2.37.7 for the 2.37.x series, and older than 2.38.2 for the 2.38.x series are vulnerable. The bug resides in the OIDC service module within the enterprise edition. Administrators using these pre‑patch versions should review their deployment and ensure the vulnerable endpoints are not exposed.
Risk and Exploitability
The CVSS score of 6 indicates a medium severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The affected endpoints are publicly reachable, meaning that an external attacker can trigger the flow without prior privileges. Because the flaw accepts a valid OIDC flow even after administrative disabling, a malicious actor could hijack credentials and gain unauthorized session access. The risk is therefore moderate, but because the vulnerability is exploitable through standard HTTP requests, organizations should prioritize remediation.
OpenCVE Enrichment
Github GHSA