Improper access control in n8n - CVE-2026-33722

 

Improper access control in n8n - CVE-2026-33722

Published: April 23, 2026


Vulnerability identifier: #VU127213
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33722
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in credential saving when referencing an external secret by name in a credential. A remote user can save a credential that references a target secret to disclose sensitive information.

The instance must have an external secrets vault configured, and the secret name must be known or guessable.


Affected software

n8n

How to mitigate CVE-2026-33722

Install security update from vendor's website.

n8n - addressed in versions 1.123.23, 2.6.4

External References

Related Security Bulletins