PT-2026-50174 · N8N · N8N

·

CVE-2026-54308

·

Published

2026-06-16

·

Updated

2026-07-16

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.25.7 n8n versions prior to 2.26.2
Description The MicrosoftAgent365Trigger and StripeTrigger nodes fail to validate inbound requests. This allows an unauthenticated attacker with knowledge of the webhook URL to submit a forged payload, triggering workflow execution with attacker-controlled data.
Recommendations Update to version 2.25.7 or later. Update to version 2.26.2 or later. Deactivate any workflows using the MicrosoftAgent365Trigger or StripeTrigger nodes as a temporary measure. Restrict network access to the n8n webhook endpoint to trusted sources only.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54308
GHSA-JVC7-762P-3743

Affected Products

N8N