CVE-2026-56353

Severity CVSS v4.0:
MEDIUM
Type:
CWE-287 Authentication Issues
Publication date:
15/07/2026
Last modified:
16/07/2026

Description

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* 1.123.22 (excluding)
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* 2.0.0 (including) 2.9.3 (excluding)
cpe:2.3:a:n8n:n8n:2.10.0:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:2.10.0:*:*:*:enterprise:node.js:*:*