n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in. | |
| Title | n8n before 2.36.2 Missing Authorization via Insights API | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T11:22:21.419Z
Updated: 2026-09-03T14:44:42.267Z
Reserved: 2026-09-03T11:05:09.078Z
Link: CVE-2026-85173
Updated: 2026-09-03T14:44:34.038Z
Status : Awaiting Analysis
Published: 2026-09-03T13:06:24.990
Modified: 2026-09-08T20:10:30.270
Link: CVE-2026-85173
No data.