Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-77079

Опубликовано: 20 авг. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) to the built-in project:admin role, gaining full administrative control of projects they had no legitimate access to.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия до 2.33.4 (исключая)
cpe:2.3:a:n8n:n8n:2.34.0:*:*:*:*:node.js:*:*

EPSS

Процентиль: 16%
0.00248
Низкий

8.8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.8
github
23 дня назад

n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) to the built-in project:admin role, gaining full administrative control of projects they had no legitimate access to.

EPSS

Процентиль: 16%
0.00248
Низкий

8.8 High

CVSS3

Дефекты

CWE-639