What is CVE-2026-65594?
CVE-2026-65594 is a vulnerability in n8n (affecting versions from 2.27.0 to before 2.29.8 and 2.30.x before 2.30.1) where the OAuth 2.1 flow fails to verify if the authenticated user has access to the workflow referenced as the OAuth resource. This impacts instances with an active MCP Server Trigger workflow, and upgrading to patched versions is recommended.
Azərbaycanca: CVE-2026-65594: n8n platformasında, OAuth 2.1 axını təqdim ediləndən sonra (2.27.0 versiyasından etibarən) autentifikasiya olunmuş istifadəçinin `OAuth resource` kimi göstərilən workflow-a icazəsinin olub-olmadığını yoxlamamaq boşluğudur. Bu, aktiv MCP Server Trigger workflow-u olan nümunələrə təsir edir. n8n-i 2.29.8 və ya 2.30.1 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the n8n platform are affected by CVE-2026-65594?
The vulnerability exists from version 2.27.0 onwards and impacts all versions prior to 2.29.8 and 2.30.1.
What must be active on an n8n instance to exploit CVE-2026-65594?
The instance must have an active MCP Server Trigger workflow to be exploited.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.