{"id":"CVE-2026-65014","aliases":["GHSA-33q9-f52j-gc75"],"url":"https://o3.security/vulnerability/CVE-2026-65014","summary":"n8n before 2.28.0 Authentication Bypass via test-webhook","details":"n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration. The impact is limited to disrupting in-progress test sessions; production webhooks, persistent workflow state, and stored data are not affected.","published":"2026-07-22T11:21:37.350Z","modified":"2026-08-12T03:51:40.583946234Z","cvss":null,"epss":{"score":0.00334,"percentile":0.2617,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"n8n","fixedVersion":"2.27.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65014.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-33q9-f52j-gc75"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65014"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/n8n-before-authentication-bypass-via-test-webhook"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.583946234Z"}}