Threat Advisory

n8n Agent Workflow Tool Bypasses Sub-Workflow Caller Policy

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, assigned CVE-2026-86996 with a CVSS score of 5.3, was discovered in n8n due to a security misconfiguration that allows unauthorized access through the Agent tool path. The flaw type is CWE-862 and affects versions >= 2.38.0, < 2.38.2 and < 2.37.7. An attacker with the ability to build an Agent can bypass the sub-workflow caller policy by attaching a workflow as an Agent tool, allowing them to call restricted workflows and read their returned values.

RECOMMENDATION:

We recommend you to update n8n to version 2.38.2 or 2.37.7.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, assigned CVE-2026-86996 with a CVSS score of 5.3, was discovered in n8n due to a security misconfiguration that allows unauthorized access through the Agent tool path. The flaw type is CWE-862 and affects versions >= 2.38.0, < 2.38.2 and < 2.37.7. An attacker with the ability to build an Agent can bypass the sub-workflow caller policy by attaching a workflow as an Agent tool, allowing them to call restricted workflows and read their returned values.

RECOMMENDATION:

We recommend you to update n8n to version 2.38.2 or 2.37.7.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu