What is CVE-2026-65015?
A privilege escalation vulnerability exists in the AI Agents feature of n8n versions prior to 2.30.1, due to missing authorization checks in the node-execution tool. A user with the 'Project Viewer' role can execute arbitrary nodes by interacting with an agent that has node tools enabled. Users should immediately upgrade to n8n version 2.30.1 or later.
Azərbaycanca: n8n platformasının 2.30.1-dən əvvəlki versiyalarında AI Agents funksionallığında imtiyaz yüksəltmə (privilege escalation) zəifliyi aşkarlanıb. Bu, 'Project Viewer' roluna malik istifadəçinin, node execution tool vasitəsilə agentlə danışaraq icazəsiz node-ları işə salmasına imkan verir. İstifadəçilərə dərhal n8n-i 2.30.1 və ya daha yuxarı versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which n8n functionality is affected by this CVE, and what does the vulnerability allow an unprivileged user to do?
CVE-2026-65015 affects the AI Agents feature of n8n. This vulnerability allows a user with the 'Project Viewer' role to execute arbitrary, unauthorized nodes by interacting with an agent via the node-execution tool, leading to privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.