CVE-2026-56350
גבוהה 7.7
תיאור (מקור, אנגלית)
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
מדדים
- CVSS 3.1
-
7.7 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N - CVSS 4.0
-
6.0 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-15/8/2026
- CWE
- CWE-285
מוצרים מושפעים
n8n: n8n
קישורים
- https://github.com/n8n-io/n8n/security/advisories/GHSA-vjf3-2gpj-233v MitigationVendor Advisory
- https://www.vulncheck.com/advisories/n8n-sso-enforcement-bypass-via-api Third Party Advisory