Improper access control in n8n - #VU141000

 

Improper access control in n8n - #VU141000

Published: August 5, 2026


Vulnerability identifier: #VU141000
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose restricted credentials.

The vulnerability exists due to improper access control in the GraphQL node credential selector logic when processing an expression-valued `Authentication` parameter with multiple attached credentials of different types. A remote user can configure the parameter to expression mode and attach at least two credentials of different types to disclose restricted credentials.

The impact is limited to the permissions of the leaked credential.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.69, 2.33.4, 2.34.1

External References

Related Security Bulletins