THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pf83-w3f9-8m37 (medium) — n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions

[GHSA] GHSA-pf83-w3f9-8m37 (medium) — n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions

medgithub_advisoriesPublished 2026-09-10

GHSA-pf83-w3f9-8m37 Severity: medium CVE: CVE-2026-86084

n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions

## Impact

The public OIDC login and callback endpoints ran the full flow whether or not OIDC was the instance's active, enabled authentication method, so turning OIDC off in Settings did not stop it issuing sessions. An administrator who disabled the provider still ha

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pf83-w3f9-8m37