MEDIUMVulnerability

CVE-2026-85173

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-85173
signal_observed_at
2026-09-16T21:37:06+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
published_at
2026-09-03T13:06:24.990
last_modified
2026-09-16T21:21:54.743

Related Entities (3)

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85173 — Ninja Signal Threat Intelligence | Ninja Signal