Authorization Bypass in n8n Credential Test Endpoint by n8n
CVE-2026-103252

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103252?

Certain versions of n8n are susceptible to an authorization bypass vulnerability within the credential test endpoint. This flaw allows attackers to exploit the authorization mechanism by providing an arbitrary project ID in the request body. Consequently, sensitive project-scoped variables can be accessed without proper validation, enabling potential exfiltration of this information to external, attacker-controlled hosts.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hemalv02
.