CVE-2026-77079

Source
https://cve.org/CVERecord?id=CVE-2026-77079
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77079.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77079
Aliases
  • GHSA-xhmh-8fgr-xqhj
Downstream
Published
2026-08-20T11:21:11Z
Modified
2026-09-03T03:48:20Z
Severity
  • 7.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H CVSS Calculator
Summary
n8n before 2.34.1 Authorization Bypass via Custom Role Deletion
Details

n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) to the built-in project:admin role, gaining full administrative control of projects they had no legitimate access to.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77079.json"
}
References

Affected packages

Git / github.com/n8n-io/n8n

Affected ranges

Type
GIT
Repo
https://github.com/n8n-io/n8n
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.34.0"
        },
        {
            "fixed": "2.34.1"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.33.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.34.0
n8n@2.*
n8n@2.34.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77079.json"