CVE-2026-103260
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Summary
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can submit resume requests without verification of the requester's identity or approval permissions, allowing unauthenticated users to advance waiting executions and trigger guarded actions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n8n-io | n8n | 0 < 2.39.6 | affected |
| n8n-io | n8n | 2.40.0 < 2.40.1 | affected |
Weaknesses
- CWE-862: Missing Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-342v-gmh6-738j
- https://www.vulncheck.com/advisories/n8n-before-2.39.6-and-2.40-x-before-2.40.1-approval-bypass-via-send-and-wait-node
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.