What is CVE-2026-72768?
CVE-2026-72768 is an SSRF protection bypass vulnerability in the MCP Client node of n8n versions before 2.32.1, allowing authenticated users to send requests to internal or blocked hosts. This flaw enables attackers to craft workflows that avoid SSRF protection mechanisms. Users should upgrade n8n to version 2.32.1 or later immediately.
Azərbaycanca: CVE-2026-72768, n8n iş axını avtomatlaşdırma platformasının 2.32.1-dən əvvəlki versiyalarında MCP Client node-da aşkar edilmiş SSRF mühafizəsindən yayınma zəifliyidir. Bu zəiflik autentifikasiya olunmuş istifadəçilərə daxili və ya bloklanmış hostlara icazəsiz sorğular göndərməyə imkan verir. n8n-i dərhal 2.32.1 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of the n8n platform are affected by CVE-2026-72768?
This vulnerability affects n8n workflow automation platform versions prior to 2.32.1.
What risk does the exploitation of CVE-2026-72768 pose?
Authenticated users can bypass SSRF protection via the MCP Client node, allowing them to send unauthorized requests to internal or blocked hosts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.