CVE-2026-56350: n8n
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
Affected products
- n8n n8n: before 2.8.0 (fixed in 2.8.0)
Published 2026-06-30. Last modified 2026-07-02.