
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33720 is an authorization bypass vulnerability in n8n, an open-source workflow automation platform, affecting all versions prior to 2.8.0. When the N8N_SKIP_AUTH_ON_OAUTH_CALLBACK environment variable is set to true, the OAuth callback handler skips ownership verification of the OAuth state parameter, enabling an attacker to hijack a victim's OAuth tokens. The vulnerability was disclosed on March 25, 2026, and a patch was released in n8n version 2.8.0. It carries a CVSS v4.0 base score of 6.3 (Medium) and a CVSS v3.1 base score of 4.2 (Medium) (GitHub Advisory, n8n Security Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): when N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true is set, the OAuth callback handler omits verification that the OAuth state parameter belongs to the authenticated user initiating the flow. An attacker who controls a credential object on the same n8n instance can craft a malicious OAuth initiation URL referencing their own credential ID, then socially engineer a victim into visiting that URL and completing the OAuth authorization flow. Because state ownership is not checked, the victim's returned OAuth tokens are written into the attacker's credential store rather than the victim's. This issue is non-default and only exploitable on instances where the environment variable has been explicitly enabled (GitHub Advisory, n8n Security Advisory).
Successful exploitation allows an attacker to capture a victim's OAuth access tokens for third-party services (e.g., Google, GitHub, or other OAuth providers integrated with n8n) and store them in credentials the attacker controls. The attacker can then use those tokens to execute n8n workflows on behalf of the victim, potentially accessing or manipulating data in connected third-party services. While availability is not directly impacted, both confidentiality and integrity of the victim's connected service data are at risk, and the stolen tokens could facilitate further lateral movement into integrated external systems (GitHub Advisory, n8n Security Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (3rd percentile), indicating a low near-term exploitation probability. Exploitation requires the non-default N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true configuration and the ability to trick a victim into interacting with a crafted OAuth URL, limiting the realistic attacker pool (GitHub Advisory).
N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true configured. This setting is non-default and may be discoverable through misconfiguration disclosures or insider knowledge.state parameter, pointing to the legitimate OAuth provider (e.g., Google OAuth endpoint).state parameter is skipped, the victim's returned OAuth tokens are stored in the attacker's credential object.state parameter's credential owner does not match the authenticated session user; unexpected OAuth token refresh or storage events associated with a credential not owned by the authenticating user./rest/oauth2-credential/callback or similar endpoints) originating from sessions that do not match the credential owner, particularly when N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true is active.N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true in the n8n environment configuration, which is a prerequisite for exploitation and should be audited (GitHub Advisory).The primary remediation is to upgrade n8n to version 2.8.0 or later, which restores ownership verification of the OAuth state parameter in the callback handler (n8n Security Advisory). If immediate upgrading is not feasible, administrators should: (1) disable N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true unless strictly required for operational reasons, and (2) restrict access to the n8n instance to fully trusted users only. These workarounds do not fully eliminate the risk and should be treated as temporary measures only (GitHub Advisory).
The vulnerability was reported by security researcher subhanUmer and published by the n8n maintainer (Jubke) via GitHub Security Advisories on March 25, 2026 (n8n Security Advisory). The advisory was picked up by standard vulnerability tracking platforms including Red Hat CVE database and ENISA's EUVD shortly after disclosure. No significant broader media coverage or notable community controversy has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."