CVE-2026-65595 HIGH

CVE-2026-65595: n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange

Vendor N8N-Io
Product n8n
Weakness CWE-269
Published July 22, 2026
Last update July 24, 2026

CVSS base score

8.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L

What the vulnerability does

01Description

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privileged user who can obtain a valid external JWT trusted by a configured issuer can use the resulting access token to invoke administrator-only Public API operations such as role escalation, user creation, and user deletion (role escalation requires an Advanced Permissions license), and, when unverified Community Package installation is enabled, achieve remote code execution.

Key dates

02Disclosure timeline

July 22, 2026 CVE published
July 24, 2026 Record updated

Related vulnerabilities

04Related CVE