{"id":"CVE-2026-56775","aliases":["GHSA-664h-gpgq-h6xx"],"url":"https://o3.security/vulnerability/CVE-2026-56775","summary":"n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints","details":"n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:execute scope. On instances using Advanced Permissions (Enterprise/Cloud) with projects and viewer roles, an authenticated user with the project:viewer role can start new evaluation test runs, cancel in-flight runs, and delete run records for workflows they only have read access to.","published":"2026-07-08T13:49:06.267Z","modified":"2026-08-12T03:51:14.596689562Z","cvss":null,"epss":{"score":0.00302,"percentile":0.22762,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"n8n","fixedVersion":"1.123.55"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.26.2"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.25.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56775.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-664h-gpgq-h6xx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56775"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/n8n-incorrect-oauth-scope-validation-in-evaluation-test-runs-endpoints"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.596689562Z"}}