Description
n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of from the server-side status computed for the requesting user. An authenticated project-scoped user (e.g., a project admin) could therefore reference files belonging to projects they have no access to and push a deletion of those projects' workflows and credentials, resulting in cross-project data destruction. Exploitation requires the Source Control (Environments) enterprise feature to be licensed, enabled, and connected to a remote repository. The issue is fixed in 1.123.76, 2.37.7, and 2.38.2.
Published: 2026-09-16
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-project data destruction via unauthorized source control push
Action: Patch Now
AI Analysis

Impact

In versions of the workflow automation platform before 1.123.76, 2.37.7, and 2.38.2 the source control push endpoint accepted a list of files supplied by the client and deleted those files without reconciling them against the server‑side state for the authenticated user. An attacker who is an authenticated project‑scoped user—such as a project administrator—can thus reference files belonging to other projects and delete their workflows and credentials. The result is loss of critical automation logic and stored secrets, effectively a form of data sabotage that only requires legitimate credentials within the platform.

Affected Systems

The affected product is n8n from n8n‑io, with vulnerable versions older than 1.123.76 for the 1.x series and older than 2.37.7 or 2.38.2 for the 2.x series. The vulnerability exists only for installations that have the Source Control (Environments) enterprise feature licensed, enabled, and connected to a remote repository.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate impact, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the enterprise Source Control feature to be activated and a legitimate project‑scoped user to submit a crafted push request, after which the attacker can delete workflows and credentials from projects to which they normally have no access.

Generated by OpenCVE AI on September 17, 2026 at 21:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update n8n to a version that includes the fix (1.123.76 or later, 2.37.7 or later, 2.38.2 or later).
  • If the Source Control (Environments) feature is not required, remove or disable it before the patch.
  • Audit project‑scoped user permissions to ensure only trusted users have administrative privileges.

Generated by OpenCVE AI on September 17, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of from the server-side status computed for the requesting user. An authenticated project-scoped user (e.g., a project admin) could therefore reference files belonging to projects they have no access to and push a deletion of those projects' workflows and credentials, resulting in cross-project data destruction. Exploitation requires the Source Control (Environments) enterprise feature to be licensed, enabled, and connected to a remote repository. The issue is fixed in 1.123.76, 2.37.7, and 2.38.2.
Title n8n before 1.123.76 Improper Authorization via Source Control Push
First Time appeared N8n
N8n n8n
Weaknesses CWE-639
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:46:50.121Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92588

cve-icon Vulnrichment

Updated: 2026-09-17T14:46:46.674Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:29.447

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key