CVE-2026-54309 | n8n-io n8n up to 2.25.6/2.26.1 MCP Endpoint missing authentication (GHSA-qrx8-25qr-5r7v)
A vulnerability was found in n8n-io n8n up to 2.25.6/2.26.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component MCP Endpoint. This manipulation causes missing authentication.
This vulnerability is tracked as CVE-2026-54309. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.