PT-2026-28078 · N8N · N8N
34Selen
+3
·
Published
2026-03-25
·
Updated
2026-03-25
·
CVE-2026-33665
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 2.4.0
n8n versions prior to 1.121.0
Description
n8n is a workflow automation platform. When Lightweight Directory Access Protocol (LDAP) authentication is enabled, n8n automatically links an LDAP identity to an existing local account if the LDAP email attribute matches the local account's email. An authenticated LDAP user who can control their LDAP email attribute can set it to match another user's email, including an administrator's, and gain full access to that account upon login. The account linkage persists even if the LDAP email is reverted, resulting in a permanent account takeover. LDAP authentication must be configured and active for this to occur.
Recommendations
Upgrade to n8n version 2.4.0 or later.
Upgrade to n8n version 1.121.0 or later.
If upgrading is not immediately possible, disable LDAP authentication until the instance can be upgraded.
If upgrading is not immediately possible, restrict LDAP directory permissions so that users cannot modify their own email attributes.
If upgrading is not immediately possible, audit existing LDAP-linked accounts for unexpected account associations.
Exploit
Fix
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N