Improper access control in n8n - CVE-2026-33722
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in credential saving when referencing an external secret by name in a credential. A remote user can save a credential that references a target secret to disclose sensitive information.
The instance must have an external secrets vault configured, and the secret name must be known or guessable.