Incorrect authorization in n8n - #VU153003
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to perform actions using credential values they are not authorized to use.
The vulnerability exists due to improper authorization validation in the shared-workflow credential check when saving a shared workflow containing nested inline workflows. A remote user can save a workflow with embedded nodes that reference inaccessible credentials to perform actions using credential values they are not authorized to use.
Inline workflows can be nested.