CRITICAL
9.9 CVE-2026-85165 Published 3 Sept 2026
n8n Workflow Editor Permissions Bypass
Worried this affects one of your servers?
The n8n workflow automation platform is affected by an expression sandbox bypass vulnerability in versions before 2.36.2.
Authenticated users with workflow-edit permission can exploit this issue to mutate host objects via expression evaluation, causing changes to persist process-wide until the service is restarted.
Reference: CVE-2026-85165 on NVD
← Back to Security News