Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33665

25
FAUCET Score

CVE-2026-33665 identifies a critical account takeover vulnerability in n8n, an open-source workflow automation platform, affecting versions prior to 2.4.0 and 1.121.0 when LDAP authentication is configured. An authenticated LDAP user could manipulate their email attribute to match an existing local account, including an administrator's, thereby gaining full and permanent access to that account. This vulnerability carries a CVSSv3.1 score of 7.5 HIGH (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating a network attack vector with high complexity but high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are public exploit codes available, though the vulnerability has received limited community and media attention. Users are advised to upgrade to n8n versions 2.4.0 or 1.121.0 or later to remediate this issue.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.121.0CPE matchmatch criteria
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
>= 2.0.0, < 2.4.0CPE matchmatch criteria
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 14th percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

npmpatch availablevia ghsa
Product: n8nFixed in: 2.4.0
npmpatch availablevia ghsa
Product: n8nFixed in: 1.121.0
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-c545-x2rh-82fchigh

n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover

Mar 25, 2026

References

github.com / n8n-io/n8n/security/advisories/GHSA-c545-x2rh-82fc
MitigationVendor Advisory