
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33665 is an improper authentication vulnerability in n8n, an open-source workflow automation platform, that allows authenticated LDAP users to perform privilege escalation and permanent account takeover. When LDAP authentication is enabled, n8n automatically links an LDAP identity to an existing local account if the LDAP email attribute matches the local account's email — without additional verification. This flaw affects n8n versions prior to 1.121.0 (v1 branch) and versions 2.0.0-rc.0 through 2.4.0 (v2 branch). It was disclosed on March 25, 2026, with patches released the same day. The vulnerability carries a CVSS v4.0 base score of 8.8 (High) and a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-287 (Improper Authentication): n8n's LDAP login flow trusts the email attribute returned by the LDAP directory to identify and link accounts, without verifying that the claimed email uniquely and securely belongs to the authenticating user. An attacker who has an authenticated LDAP account and the ability to modify their own LDAP email attribute can set it to match the email address of any existing local n8n account — including an administrator's. Upon the next login, n8n silently links the attacker's LDAP identity to the victim's local account, granting full access. Critically, the account linkage persists in n8n's database even after the LDAP email attribute is reverted, making the takeover permanent. Exploitation requires LDAP authentication to be configured and active (a non-default setting) and the attacker must have write access to their own LDAP email attribute (GitHub Advisory).
Successful exploitation allows an authenticated LDAP user to permanently take over any n8n account, including administrator accounts, resulting in full confidentiality and integrity compromise of the n8n instance. An attacker with administrative access could read all workflow configurations (which may contain API keys, credentials, and sensitive business logic), modify or delete workflows, and pivot to connected external systems via n8n's integrations. The persistence of the account linkage means the compromise survives credential resets and LDAP attribute reversions, making remediation without patching extremely difficult (GitHub Advisory, Github Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.013% (0.03% per GitHub Advisory), placing it in the 9th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation requires a low-privilege LDAP account and the ability to modify one's own LDAP email attribute, which may be restricted in hardened directory environments, contributing to the higher attack complexity rating in CVSS v3.1.
ldapmodify, an LDAP admin GUI, or a self-service portal), change the attacker's own LDAP mail attribute to match the email address of the target n8n account (e.g., admin@example.com).mail attribute, particularly if the new value matches another user's registered email in n8n, followed shortly by an n8n login event.user_identity or equivalent account-linking table associating an LDAP identity with a local account that previously had no LDAP linkage.The vulnerability is fixed in n8n versions 2.4.0 (v2 branch) and 1.121.0 (v1 branch); upgrading to one of these versions or later is the recommended remediation (GitHub Advisory). If immediate upgrade is not possible, administrators should apply the following temporary mitigations in order of priority:
mail (email) attributes.Note that these workarounds do not fully remediate the risk, as any linkages already established will persist.
The advisory was published by the n8n security team (credited to reporters weblover12, 34selen, B0RI, and jh-hack) on March 25, 2026, with patches released simultaneously (GitHub Advisory). The vulnerability was detected by Qualys (detection ID 5009652) and indexed by multiple vulnerability tracking platforms shortly after disclosure. No significant public researcher commentary, social media discussion, or media coverage beyond standard vulnerability database indexing has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."