Improper access control in n8n - CVE-2026-54307

 

Improper access control in n8n - CVE-2026-54307

Published: June 16, 2026


Vulnerability identifier: #VU134557
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54307
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access credentials owned by other users.

The vulnerability exists due to improper access control in specific public API endpoints when handling credential references from shared workflows. A remote user can reference credentials they do not own to access credentials owned by other users.

This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor.


Affected software

n8n

How to mitigate CVE-2026-54307

Install security update from vendor's website.

n8n - addressed in versions 1.123.55, 2.25.7, 2.26.2

External References

Related Security Bulletins