CVE-2026-56353

EUVD-2026-44626
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.36%
Affected Products (NVD)
VendorProductVersion
n8nn8n
𝑥
< 1.123.22
n8nn8n
2.0.0 ≤
𝑥
< 2.9.3
n8nn8n
2.10.0
n8nn8n
2.10.0
𝑥
= Vulnerable software versions