CVE-2026-103260

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
4.0
MEDIUM

Description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can submit resume requests without verification of the requester's identity or approval permissions, allowing unauthenticated users to advance waiting executions and trigger guarded actions.

Published
October 1, 2026 11:17 AM
Last Modified
October 1, 2026 11:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-862

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.