Back

MEDIUM

n8n before 2.28.0 Authentication Bypass via test-webhook

Published Jul 22, 2026

Description

n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration. The impact is limited to disrupting in-progress test sessions; production webhooks, persistent workflow state, and stored data are not affected.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 22, 2026
Updated Jul 22, 2026
Reserved Jul 21, 2026
CISA Vulnrichment
Updated Jul 22, 2026
NVD
Status Analyzed
Modified Jul 27, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-33Q9-F52J-GC75