A high-severity flaw tracked as CVE-2026-65595 affects n8n versions before 2.30.1 and, on a separate branch, before 2.29.8. The vulnerability stems from the Token Exchange module assigning all Public API scopes to JWT-derived access tokens after validating an external JWT from a trusted issuer, allowing a low-privileged user to gain administrator-level Public API access when both Token Exchange and Public API are enabled. The issue is rated CVSS v4.0 8.9 and classified as CWE-269 Improper Privilege Management.
Successful exploitation can let an attacker perform admin-only actions including creating or deleting users, escalating roles, modifying workflows, reading database credentials stored in connection configurations, and exporting sensitive system data. In deployments that also allow installation of unverified Community Packages, the compromise can be extended to remote code execution on the n8n host, creating a path to full takeover of the automation platform and its underlying server.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A high-severity privilege escalation vulnerability, CVE-2026-65595, was publicly disclosed affecting n8n versions before 2.30.1 and before 2.29.8 on a separate branch. The flaw allows a low-privileged user with a valid external JWT to gain administrator-level Public API access, and in some configurations may lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.