Improper access control in n8n - CVE-2026-54307

 

Improper access control in n8n - CVE-2026-54307

Published: June 16, 2026


Vulnerability identifier: #VU134557
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-54307
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: n8n
Affected software:
n8n

Detailed vulnerability description

The vulnerability allows a remote user to access credentials owned by other users.

The vulnerability exists due to improper access control in specific public API endpoints when handling credential references from shared workflows. A remote user can reference credentials they do not own to access credentials owned by other users.

This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor.


How to mitigate CVE-2026-54307

Install security update from vendor's website.

Sources