CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-56350

CVE-2026-56350: SSO Enforcement Bypass in n8n via API Parameter Pollution / Mass Assignment

Amit Schendel
Amit Schendel
Senior Security Researcher

Jul 1, 2026·6 min read·45 visits

Executive Summary (TL;DR)

Authenticated SSO users can bypass SSO enforcement and log in with email/password credentials by exploiting a mass assignment flaw in n8n's settings endpoint.

A mass assignment vulnerability (CWE-915) in n8n's self-service settings API endpoint (PATCH /me/settings) allows authenticated Single Sign-On (SSO) users to disable SSO enforcement for their accounts by injecting administrative parameters. This bypasses organizational identity provider controls and multi-factor authentication (MFA).

Vulnerability Overview

The vulnerability, tracked as CVE-2026-56350 and GHSA-vjf3-2gpj-233v, represents an improper authorization (CWE-285) and mass assignment (CWE-915) flaw in the self-service settings API of the n8n workflow automation platform. In affected versions prior to 2.8.0, authenticated users who log in using Single Sign-On (SSO) can modify administrative-level authentication preferences. By executing a crafted API call, users can disable SSO enforcement policies assigned to their specific account profiles.

The vulnerability resides within the /me/settings endpoint, which is exposed to handle standard user configuration updates. The endpoint failed to restrict inputs to non-sensitive user parameters. This exposure allows a standard user to manipulate internal flags that govern identity verification and credential policies, extending their privilege limits beyond designed constraints.

The exploitation of this flaw does not require administrative rights, making it accessible to any authenticated standard user. The primary consequence is the subversion of centralized access controls, including Multi-Factor Authentication (MFA) and Identity Provider (IdP) revocation policies, posing a significant risk to enterprise tenant security.

Root Cause Analysis

The root cause of CVE-2026-56350 lies in the direct mapping of request payloads to a high-privilege Data Transfer Object (DTO) model without contextual validation. When a user submits a configuration update, the backend processes the request via the MeController using the NestJS framework. The application handles requests to the PATCH /me/settings route by binding the body of the HTTP request directly to the SettingsUpdateRequestDto class.

This shared SettingsUpdateRequestDto schema contains both standard, low-privilege settings (such as onboarding status) and high-privilege configuration parameters. Among these high-privilege parameters is allowSSOManualLogin, a boolean flag designed to control whether a user can bypass the organization's enforced SSO policy to log in with a local password.

Because the endpoint did not implement validation to strip unprivileged parameters or utilize a context-specific DTO, the binding engine processed any provided key-value pairs matching the schema. When the controller updated the database record, it saved the attacker-supplied allowSSOManualLogin flag. This direct binding mechanism constitutes a classic mass assignment vulnerability (CWE-915).

Code Analysis

The vulnerable implementation of the settings update endpoint utilized the general SettingsUpdateRequestDto model, which exposed administrative fields directly to self-service updates. Below is the vulnerable controller implementation before the application of the patch.

// Vulnerable Controller Path: packages/cli/src/controllers/me.controller.ts
@Patch('/settings')
async updateCurrentUserSettings(
    req: AuthenticatedRequest,
    _: Response,
    @Body payload: SettingsUpdateRequestDto, // Vulnerable: Binds request directly to the administrative DTO
): Promise<User['settings']> {
    const { id } = req.user;
    // Database update operations process the entirety of the payload

To remediate this issue, the development team created a specialized, restricted DTO named UserSelfSettingsUpdateRequestDto. This new schema defines only a strict subset of safe properties that a standard user is authorized to modify, omitting the high-privilege administrative settings.

// Patched DTO: packages/@n8n/api-types/src/dto/user/user-self-settings-update-request.dto.ts
import { z } from 'zod';
import { Z } from 'zod-class';
 
export class UserSelfSettingsUpdateRequestDto extends Z.class({
	easyAIWorkflowOnboarded: z.boolean().optional(),
	dismissedCallouts: z.record(z.string(), z.boolean()).optional(),
}) {}

The controller was then modified to restrict the input parameter binding type to this newly introduced UserSelfSettingsUpdateRequestDto class.

// Patched Controller Path: packages/cli/src/controllers/me.controller.ts
@Patch('/settings')
async updateCurrentUserSettings(
	req: AuthenticatedRequest,
	_: Response,
	@Body payload: UserSelfSettingsUpdateRequestDto, // Patched: Binds request to the restricted DTO
): Promise<User['settings']> {
	const { id } = req.user;

This structural separation ensures that any attempt by a user to submit unauthorized parameters like allowSSOManualLogin will be caught during the schema parsing phase and stripped from the input object before reaching the database logic.

Exploitation Methodology

An attacker must first possess a valid, authenticated session within the target n8n instance, typically established via the standard Single Sign-On (SSO) login flow. Once logged in, the attacker can leverage standard browser developer tools or command-line HTTP clients to extract their active session identifier or JSON Web Token (JWT).

With the active session identifier, the attacker constructs an HTTP PATCH request directed at the /me/settings endpoint. In the JSON body of this request, the attacker appends the administrative parameter "allowSSOManualLogin": true alongside expected configuration parameters.

PATCH /me/settings HTTP/1.1
Host: n8n.target.org
Authorization: Bearer <JWT_TOKEN>
Content-Type: application/json
 
{
  "easyAIWorkflowOnboarded": true,
  "allowSSOManualLogin": true
}

Upon processing the request, the vulnerable n8n backend accepts the payload and updates the database row corresponding to the attacker's user profile. The attacker can then utilize the local credential creation or recovery endpoints to associate a local password with their email address. Following this modification, the attacker can log in directly using conventional credentials, completely bypassing the external identity provider controls and any configured Multi-Factor Authentication (MFA) mechanisms.

To visually illustrate this process, the following diagram depicts the message exchange leading to the unauthorized policy update and subsequent authentication bypass.

Impact Assessment

The security implications of CVE-2026-56350 are centered on the subversion of centralized authentication and identity enforcement policies. When an attacker successfully overrides the SSO enforcement flag, the centralized Identity Provider (IdP) loses control over the user's access path to the n8n application.

This bypass undermines organizational security posture by rendering standard offboarding procedures ineffective. If an administrator disables or revokes an employee's account within the centralized IdP (such as Okta or Entra ID), the employee can still maintain persistent access to the n8n workspace via their direct email and password credentials.

Furthermore, this vulnerability renders any IdP-level security policies, such as conditional access rules, IP geofencing, or mandatory hardware-token multi-factor authentication (MFA), completely obsolete for the affected account. The impact of the vulnerability is reflected in its CVSS score of 6.3, highlighting the severe integrity compromise resulting from unauthorized authentication policy modification.

Remediation and Mitigation

The primary and recommended mitigation is the immediate upgrade of all n8n instances to version 2.8.0 or later. This version contains the specialized validation schemas that prevent unauthorized parameter assignment. For container-based environments, this is achieved by specifying the fixed tag in the deployment configuration.

If an immediate upgrade is not feasible, security administrators should perform a direct audit of the database to identify compromised accounts. Executing a query to inspect the user settings table can pinpoint any standard accounts that have successfully disabled the SSO requirement.

SELECT id, email, settings FROM "user" WHERE settings::jsonb ->> 'allowSSOManualLogin' = 'true';

Additionally, organizations can implement temporary Web Application Firewall (WAF) rules to inspect traffic heading to the /me/settings and /api/v1/me/settings endpoints. The WAF should block any PATCH requests that contain the string "allowSSOManualLogin" within the request body, effectively mitigating the exploit vector until a patch can be applied.

Official Patches

n8nFix Commit in GitHub
n8nv2.8.0 Official Release

Fix Analysis (1)

Technical Appendix

CVSS Score
6.3/ 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N

Affected Systems

n8n (npm package)

Affected Versions Detail

Product
Affected Versions
Fixed Version
n8n
n8n
< 2.8.02.8.0
AttributeDetail
CWE IDCWE-285, CWE-915
Attack VectorNetwork
CVSS v3.1 Score6.3 (Medium)
CVSS v4.0 Score6.0 (Medium)
Exploit StatusPoC / Simulated
CISA KEV StatusNot Listed
Remediation StatusPatched in v2.8.0

MITRE ATT&CK Mapping

T1563Subvert Active Gates / SSO Bypass
Defense Evasion
T1078Valid Accounts
Persistence
CWE-285
Improper Authorization

The software fails to restrict standard user input fields, allowing standard parameters to manipulate administrative-only variables via over-posting.

Vulnerability Timeline

n8n fixes the vulnerability core in commit a70b2ea379086da3de103bb84811e88cadf29976
2026-02-05
GitHub Advisory GHSA-vjf3-2gpj-233v published
2026-02-26
CVE-2026-56350 published in NVD
2026-06-30

References & Sources

  • [1]GitHub Security Advisory GHSA-vjf3-2gpj-233v
  • [2]VulnCheck Security Advisory
  • [3]Fix Commit
  • [4]n8n Release v2.8.0

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•GHSA-RCW4-F5RP-G42V
7.5

GHSA-RCW4-F5RP-G42V: Uncontrolled Resource Consumption and Decompression Bomb Protection Bypass in adm-zip

A critical denial-of-service vulnerability in the adm-zip npm package allows attackers to bypass decompression-bomb protections introduced in version 0.5.18. By declaring the uncompressed file size as exactly 0, an attacker can disable the maxOutputLength constraint in the Node.js zlib wrapper, leading to complete system memory exhaustion and process crashes.

Alon Barad
Alon Barad
1 views•8 min read
•about 2 hours ago•CVE-2026-81872
6.3

CVE-2026-81872: CPU Exhaustion via Tight Loop in OpenTelemetry-Go BatchingProcessor

An uncontrolled resource consumption vulnerability in the logs SDK of OpenTelemetry-Go allows remote attackers to trigger a denial of service. Under conditions of downstream exporter backpressure, the BatchingProcessor enters a tight loop, exhausting CPU resources. This occurs because the processor immediately schedules retry attempts without waiting for its ticker interval, spinning continuously when the internal queue remains filled above the batch size. The issue affects all versions prior to v0.21.0 of the go.opentelemetry.io/otel/sdk/log package.

Alon Barad
Alon Barad
3 views•7 min read
•about 3 hours ago•CVE-2026-76844
7.4

CVE-2026-76844: Path Traversal in webpack-dev-middleware via Incomplete Prefix Validation

CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware affecting multiple version branches. It stems from an incomplete fix for CVE-2024-29180 when serving files via a physical filesystem with a non-slash-terminated publicPath configuration. Attackers can bypass directory validation to access files situated one level above the intended output directory.

Amit Schendel
Amit Schendel
4 views•5 min read
•about 10 hours ago•CVE-2026-77310
5.3

CVE-2026-77310: Server-Side Request Forgery via DNS Resolution in jackson-databind

A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.

Alon Barad
Alon Barad
7 views•4 min read
•about 11 hours ago•CVE-2026-19032
5.3

CVE-2026-19032: Insecure Deserialization and Class Loading via java.nio.file.Path Resolution in FasterXML jackson-databind

An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.

Alon Barad
Alon Barad
10 views•6 min read
•about 12 hours ago•CVE-2026-68497
7.5

CVE-2026-68497: CPU Denial of Service via XML Datatype Deserialization in FasterXML jackson-databind

CVE-2026-68497 is a high-severity CPU Denial of Service (DoS) vulnerability in jackson-databind. It arises because the library bypasses default input constraint checks when parsing stringified XML datatypes, subsequently passing arbitrary-length inputs to JDK constructors with quadratic execution complexity.

Alon Barad
Alon Barad
16 views•6 min read