Vulnerability Description
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration. The impact is limited to disrupting in-progress test sessions; production webhooks, persistent workflow state, and stored data are not affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| N8N | N8N | >= 2.27.0, < 2.27.4 |
Related Weaknesses (CWE)
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-33q9-f52j-gc75MitigationVendor Advisory
- https://www.vulncheck.com/advisories/n8n-before-authentication-bypass-via-test-wThird Party Advisory
FAQ
What is CVE-2026-65014?
CVE-2026-65014 is a vulnerability with a CVSS score of 5.3 (MEDIUM). n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated net...
How severe is CVE-2026-65014?
CVE-2026-65014 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-65014?
Check the references section above for vendor advisories and patch information. Affected products include: N8N N8N.