Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, and publication push events were also broadcast to clients that could not access the affected workflow, disclosing workflow IDs, version IDs, and activation error details. The affected paths include packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from a missing userId filter in the /rest/active-workflows endpoint and related event notifier services. As a result, any authenticated member can retrieve the list of all active workflow IDs on the instance, and can also receive lifecycle events—including activation, deactivation, publication and errors—for workflows they are not authorized to access. The disclosed data includes workflow IDs, version IDs and activation error details, which can help an attacker enumerate existing workflows, discover workflow versions, and potentially predict scheduling or use patterns. The weakness is an access control flaw, identified as CWE-862.

Affected Systems

The open source n8n workflow automation platform from n8n-io is impacted. Versions earlier than 1.123.76, 2.37.7, and 2.38.2 are vulnerable. The issue is fixed in the corresponding releases of those versions.

Risk and Exploitability

The CVSS score for this issue is 5.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated member status to trigger the affected endpoints; thus exploitation is feasible for any user with valid credentials, though it does not allow arbitrary code execution or privilege escalation. The risk is therefore moderate, mainly associated with unintended information leakage of workflow identifiers and error details.

Generated by OpenCVE AI on September 9, 2026 at 08:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to v1.123.76 or later, v2.37.7, or v2.38.2 to eliminate the missing filter flaw.
  • Ensure that any custom or additional configuration for the /rest/active-workflows endpoint and event broadcasting enforces proper userId filtering and restricts access to authorized users only.
  • Monitor API logs for attempts to list active workflows or subscribe to events from unauthorized users and set alerts for anomalous activity.

Generated by OpenCVE AI on September 9, 2026 at 08:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-65xw-2v52-jhxc n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
History

Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, and publication push events were also broadcast to clients that could not access the affected workflow, disclosing workflow IDs, version IDs, and activation error details. The affected paths include packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T15:40:12.574Z

Reserved: 2026-09-08T16:44:23.781Z

Link: CVE-2026-86994

cve-icon Vulnrichment

Updated: 2026-09-09T15:40:09.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:17.960

Modified: 2026-09-10T21:01:20.000

Link: CVE-2026-86994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:45:17Z

Weaknesses