{"id":"GHSA-35q8-9mj6-wjmf","summary":"n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner","details":"## Impact\nn8n's Enterprise SSO instance-role provisioning maps a role claim asserted by the configured Identity Provider (IdP) to an n8n global role and applies it during authentication. The provisioning path did not prevent assignment of the `global:owner` role, unlike the token-exchange identity path, which explicitly rejects it. As a result, an SSO-authenticated user whose instance-role claim resolves to `global:owner` is provisioned as an instance owner, obtaining full administrative control over all workflows, credentials, users, and instance configuration.\n\nThis is a privilege-escalation issue that is exploitable only under specific conditions. It affects instances where Enterprise SSO is configured and instance-role provisioning is enabled via the `N8N_SSO_SCOPES_PROVISION_INSTANCE_ROLE` flag, which is disabled by default. Exploitation additionally requires the attacker to control the value of the instance-role claim issued by the IdP. As this claim is typically an administrator-managed attribute, exploitation generally requires control over the IdP or its claim-to-role mapping, or a permissive IdP configuration in which a lower-privileged user can influence the claim value. Deployments that do not use Enterprise SSO, or that have instance-role provisioning disabled, are not affected.\n\n## Patches\nThe issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability.\n\n## Workarounds\nIf upgrading is not immediately possible, administrators should consider the following temporary mitigations:\n- Disable instance-role provisioning by unsetting or setting `N8N_SSO_SCOPES_PROVISION_INSTANCE_ROLE=false`.\n- Audit IdP claim mappings to ensure no user-controllable attribute can supply the instance-role claim value.\n- Restrict SSO access to fully trusted users only.\n\nThese workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.","aliases":["CVE-2026-65016"],"modified":"2026-07-22T22:26:48.326763Z","published":"2026-07-22T22:04:04Z","database_specific":{"github_reviewed_at":"2026-07-22T22:04:04Z","nvd_published_at":null,"cwe_ids":["CWE-639"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-35q8-9mj6-wjmf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65016"},{"type":"PACKAGE","url":"https://github.com/n8n-io/n8n"},{"type":"WEB","url":"https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.64"},{"type":"WEB","url":"https://github.com/n8n-io/n8n/releases/tag/n8n@2.29.8"},{"type":"WEB","url":"https://github.com/n8n-io/n8n/releases/tag/n8n@2.30.1"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/n8n-before-privilege-escalation-via-sso-instance-role"}],"affected":[{"package":{"name":"n8n","ecosystem":"npm","purl":"pkg:npm/n8n"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.123.64"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-35q8-9mj6-wjmf/GHSA-35q8-9mj6-wjmf.json"}},{"package":{"name":"n8n","ecosystem":"npm","purl":"pkg:npm/n8n"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.30.0"},{"fixed":"2.30.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-35q8-9mj6-wjmf/GHSA-35q8-9mj6-wjmf.json"}},{"package":{"name":"n8n","ecosystem":"npm","purl":"pkg:npm/n8n"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0-rc.0"},{"fixed":"2.29.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-35q8-9mj6-wjmf/GHSA-35q8-9mj6-wjmf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}