{"id":"CVE-2026-77079","aliases":["GHSA-xhmh-8fgr-xqhj"],"url":"https://o3.security/vulnerability/CVE-2026-77079","summary":"n8n before 2.34.1 Authorization Bypass via Custom Role Deletion","details":"n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) to the built-in project:admin role, gaining full administrative control of projects they had no legitimate access to.","published":"2026-08-20T11:21:11.692Z","modified":"2026-08-22T03:58:13.897495856Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77079.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-xhmh-8fgr-xqhj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77079"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/n8n-before-authorization-bypass-via-custom-role-deletion"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-22T03:58:13.897495856Z"}}