Improper Authorization in n8n - #VU139115
Published: July 22, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the HTTP Request node genericAuthType credential authorization check when processing an expression-based credential type. A remote user can reference another user's credential identifier in a shared workflow to disclose sensitive information.
Exploitation requires edit access to a shared workflow and knowledge of the target credential's identifier.