HIGHVulnerability
CVE-2026-77079
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) to the built-in project:admin role, gaining full administrative control of projects they had no legitimate access to.
Properties
- severity
- HIGH
- score
- 8.8
- epss_score
- 0.00248
- cve_id
- CVE-2026-77079
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-20T12:16:39.263
- last_modified
- 2026-09-01T19:45:02.283
- epss_percentile
- 0.15972
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Authorization Bypass Through User-Controlled Key
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (2)
→[Product]
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph