What is CVE-2026-65014?
In n8n versions before 2.28.0 (and before 2.27.4 on the 2.27.x branch), the DELETE /${restEndpoint}/test-webhook/:id endpoint is registered before authentication middleware, allowing unauthenticated attackers who know a workflow ID to cancel active test webhook registrations. Users should immediately upgrade to version 2.28.0 or 2.27.4 to mitigate this vulnerability.
Azərbaycanca: n8n platformasının 2.28.0 (və 2.27.x branch üzrə 2.27.4) versiyalarından əvvəlki buraxılışlarında autentifikasiya tətbiq edilmədən qeydiyyatdan keçən DELETE /${restEndpoint}/test-webhook/:id endpoint-i, autentifikasiya olunmamış şəbəkə istifadəçilərinə workflow ID-sini bilməklə aktiv test webhook qeydiyyatını ləğv etməyə imkan verir. Təsirə məruz qalmamaq üçün n8n-i dərhal 2.28.0 və ya 2.27.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What issue does CVE-2026-65014 cause in the n8n platform?
This vulnerability allows unauthenticated network attackers to cancel active test webhook registrations by knowing the workflow ID via the DELETE /${restEndpoint}/test-webhook/:id endpoint.
Which n8n versions should be updated to in order to protect against CVE-2026-65014?
To protect against the vulnerability, users should immediately upgrade n8n to version 2.28.0, or to version 2.27.4 if using the 2.27.x branch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.