CVE-2026-33665 identifies a critical account takeover vulnerability in n8n, an open-source workflow automation platform, affecting versions prior to 2.4.0 and 1.121.0 when LDAP authentication is configured. An authenticated LDAP user could manipulate their email attribute to match an existing local account, including an administrator's, thereby gaining full and permanent access to that account. This vulnerability carries a CVSSv3.1 score of 7.5 HIGH (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating a network attack vector with high complexity but high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are public exploit codes available, though the vulnerability has received limited community and media attention. Users are advised to upgrade to n8n versions 2.4.0 or 1.121.0 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.121.0CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
>= 2.0.0, < 2.4.0CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.