Improper access control in n8n - #VU141000
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose restricted credentials.
The vulnerability exists due to improper access control in the GraphQL node credential selector logic when processing an expression-valued `Authentication` parameter with multiple attached credentials of different types. A remote user can configure the parameter to expression mode and attach at least two credentials of different types to disclose restricted credentials.
The impact is limited to the permissions of the leaked credential.