Improper access control in n8n - CVE-2026-54307
Published: June 16, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to access credentials owned by other users.
The vulnerability exists due to improper access control in specific public API endpoints when handling credential references from shared workflows. A remote user can reference credentials they do not own to access credentials owned by other users.
This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor.