PatchSiren cyber security CVE debrief
CVE-2026-65015 n8n-io CVE debrief
A high-severity privilege escalation vulnerability was discovered in n8n versions before 2.30.1. The vulnerability exists in the AI Agents feature, where the node-execution tool lacks proper authorization checks. A Project Viewer user can exploit this vulnerability by chatting with an agent that has node tools enabled, allowing them to execute arbitrary nodes and access credential secrets without proper authorization verification.
- Vendor
- n8n-io
- Product
- n8n
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of n8n versions before 2.30.1 should be aware of this vulnerability and take immediate action to upgrade to a patched version. Additionally, administrators and security teams responsible for monitoring and mitigating potential threats in their environments should prioritize this vulnerability due to its high severity and potential impact.
Technical summary
The CVE-2026-65015 vulnerability has a CVSS score of 7.2 and is classified as HIGH severity. It affects the n8n workflow automation tool, specifically the AI Agents feature. The vulnerability allows a Project Viewer user to escalate privileges by interacting with an agent that has node tools enabled, potentially leading to unauthorized access to sensitive information and execution of arbitrary nodes.
Defensive priority
High priority should be given to patching this vulnerability due to its high severity and potential for privilege escalation. Administrators should ensure that n8n is upgraded to version 2.30.1 or later to mitigate this vulnerability.
Recommended defensive actions
- Upgrade n8n to version 2.30.1 or later
- Review and restrict Project Viewer user privileges
- Monitor AI Agents feature usage and node tool execution
- Implement additional access controls and authorization checks
- Perform vulnerability scanning to identify potentially exposed systems
- Review system logs for suspicious activity related to node tool execution
- Verify that all node tools are properly configured and secured
Evidence notes
The CVE record was published on 2026-07-22T12:18:18.587Z and has not been modified since then. The NVD entry is currently undergoing analysis. Limited information is available about the specific affected scope and vendor remediation efforts.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T12:18:18.587Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.