SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-56353

MEDIUM · CVSS 4.8 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Chat Trigger node in n8n, when configured with n8n User Auth, is vulnerable to an authentication bypass, allowing unauthorized access to the webhook endpoint without valid credentials. This issue affects versions prior to 1.123.22 and 2.9.3, as well as the 2.10.0 release. Organizations utilizing n8n with this configuration should prioritize updating to the patched versions to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56353
Severity
MEDIUM
CVSS
4.8
EPSS
0.23%

Original NVD Description

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)