Authorization bypass through user-controlled key in n8n - CVE-2026-33663
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through user-controlled key in the credential resolution path and credentials permission checker when resolving and executing workflows with generic HTTP credentials. A remote user can resolve another user's credential ID and execute a workflow to disclose sensitive information.
This issue affects Community Edition only, and native integration credential types such as slackApi, openAiApi, and postgres are not affected.