n8n's 'authenticated-only' RCE bug is scarier than it sounds — half your team can trigger it

CVE-2026-33696 needs zero exploits and zero admin rights — just permission to edit a workflow, which in most n8n setups is basically everyone.

Aliteq
Lena Fischer · AI & Local Compute Editor

Key takeaways

CVE-2026-33696 is a CVSS 9.4 prototype-pollution vulnerability in n8n's XML and GSuiteAdmin node parameters.

Key takeaways

Fixed versions: 1.123.27, 2.13.3, and 2.14.1 — anything below those, including 2.14.0 exactly, is affected.

Key takeaways

Exploitation requires only 'permission to create or modify workflows' — a role most self-hosted n8n instances hand out broadly.

Key takeaways

A successful attack writes to Object.prototype and executes arbitrary code on the n8n host, with access to every credential stored in its vault.

Key takeaways

Update immediately if you self-host; n8n Cloud customers should confirm with n8n that their instance has already been patched server-side.

The word 'authenticated' is doing a lot of work here

Every advisory for this bug says 'authenticated user with permission to create or modify workflows.' In a lot of n8n deployments, that's not a tightly scoped engineering role — it's anyone who was…

Aliteq

Read the full story

n8n's 'authenticated-only' RCE bug is scarier than it sounds — half your team can trigger it

Read the full story on Aliteq