GHSA-pf83-w3f9-8m37: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
Summary
n8n (a workflow automation platform) had a security flaw where OIDC endpoints (the login pathways that use OIDC, which is a single sign-on system) continued to work and issue valid sessions even after an administrator disabled OIDC in the settings. This affected n8n Enterprise instances where OIDC had been set up previously.
Solution / Mitigation
The issue has been fixed in n8n versions 1.123.76, 2.37.7, and 2.38.2. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators can temporarily disable or revoke the corresponding application or client at the IdP (identity provider, the system that handles login) level to prevent the OIDC flow from completing, or restrict network-level access to the n8n instance to trusted users only. The source notes these workarounds do not fully remediate the risk and should only be used as short-term measures.
Vulnerability Details
EPSS: 0.3%
Yes
September 10, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://github.com/advisories/GHSA-pf83-w3f9-8m37
First tracked: September 10, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 65%