PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65015 n8n-io CVE debrief

A high-severity privilege escalation vulnerability was discovered in n8n versions before 2.30.1. The vulnerability exists in the AI Agents feature, where the node-execution tool lacks proper authorization checks. A Project Viewer user can exploit this vulnerability by chatting with an agent that has node tools enabled, allowing them to execute arbitrary nodes and access credential secrets without proper authorization verification.

Vendor
n8n-io
Product
n8n
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of n8n versions before 2.30.1 should be aware of this vulnerability and take immediate action to upgrade to a patched version. Additionally, administrators and security teams responsible for monitoring and mitigating potential threats in their environments should prioritize this vulnerability due to its high severity and potential impact.

Technical summary

The CVE-2026-65015 vulnerability has a CVSS score of 7.2 and is classified as HIGH severity. It affects the n8n workflow automation tool, specifically the AI Agents feature. The vulnerability allows a Project Viewer user to escalate privileges by interacting with an agent that has node tools enabled, potentially leading to unauthorized access to sensitive information and execution of arbitrary nodes.

Defensive priority

High priority should be given to patching this vulnerability due to its high severity and potential for privilege escalation. Administrators should ensure that n8n is upgraded to version 2.30.1 or later to mitigate this vulnerability.

Recommended defensive actions

  • Upgrade n8n to version 2.30.1 or later
  • Review and restrict Project Viewer user privileges
  • Monitor AI Agents feature usage and node tool execution
  • Implement additional access controls and authorization checks
  • Perform vulnerability scanning to identify potentially exposed systems
  • Review system logs for suspicious activity related to node tool execution
  • Verify that all node tools are properly configured and secured

Evidence notes

The CVE record was published on 2026-07-22T12:18:18.587Z and has not been modified since then. The NVD entry is currently undergoing analysis. Limited information is available about the specific affected scope and vendor remediation efforts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T12:18:18.587Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.