Authorization bypass through user-controlled key in n8n - CVE-2026-33663

 

Authorization bypass through user-controlled key in n8n - CVE-2026-33663

Published: April 23, 2026


Vulnerability identifier: #VU127205
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33663
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in the credential resolution path and credentials permission checker when resolving and executing workflows with generic HTTP credentials. A remote user can resolve another user's credential ID and execute a workflow to disclose sensitive information.

This issue affects Community Edition only, and native integration credential types such as slackApi, openAiApi, and postgres are not affected.


Affected software

n8n

How to mitigate CVE-2026-33663

Install security update from vendor's website.

n8n - addressed in versions 1.123.27, 2.13.3, 2.14.1

External References

Related Security Bulletins