Improper access control in n8n - #VU127219
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in dynamic-node-parameters endpoints when handling requests with a supplied credential reference. A remote user can send a specially crafted request with a foreign credential ID and an attacker-controlled destination URL to disclose sensitive information.
The issue affects nodes that resolve credentials dynamically through these endpoints.