What is CVE-2026-65595?
CVE-2026-65595 vulnerability exists in n8n's Token Exchange module. It incorrectly assigns full Public API scopes to JWTs regardless of the user's role, allowing low-privileged users to gain elevated access. Upgrading to versions 2.30.1 or 2.29.8 resolves this issue.
Azərbaycanca: CVE-2026-65595 zəifliyi n8n platformasının Token Exchange modulunda aşkarlanıb. İstifadəçi rolundan asılı olmayaraq JWT-lərə bütün Public API icazələri verildiyi üçün aşağı səlahiyyətli şəxslər əlavə imtiyazlar əldə edə bilər. 2.30.1 və 2.29.8 versiyalarına yeniləməklə bu problemi həll etmək olar.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
What issue does CVE-2026-65595 cause in the n8n platform?
This vulnerability allows low-privileged users to gain elevated access because the Token Exchange module incorrectly assigns full Public API scopes to JWTs regardless of the user's role.
Which versions of n8n should be upgraded to in order to fix CVE-2026-65595?
Upgrading to versions 2.30.1 or 2.29.8 is recommended to resolve this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.