Moderate severityNVD Advisory· Published Jul 22, 2026· Updated Jul 22, 2026
n8n before 2.28.0 Authentication Bypass via test-webhook
CVE-2026-65014
Description
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration. The impact is limited to disrupting in-progress test sessions; production webhooks, persistent workflow state, and stored data are not affected.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
n8nnpm | < 2.27.4 | 2.27.4 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-33q9-f52j-gc75ghsaADVISORY
- github.com/n8n-io/n8n/security/advisories/GHSA-33q9-f52j-gc75ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-65014ghsaADVISORY
- www.vulncheck.com/advisories/n8n-before-authentication-bypass-via-test-webhookghsathird-party-advisoryWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
News mentions
0No linked articles in our index yet.