Authorization Bypass in n8n Credential Test Endpoint by n8n
CVE-2026-103252
7.1HIGH
What is CVE-2026-103252?
Certain versions of n8n are susceptible to an authorization bypass vulnerability within the credential test endpoint. This flaw allows attackers to exploit the authorization mechanism by providing an arbitrary project ID in the request body. Consequently, sensitive project-scoped variables can be accessed without proper validation, enabling potential exfiltration of this information to external, attacker-controlled hosts.
Affected Version(s)
n8n 0 < 1.123.80
n8n 2.0.0 < 2.39.6
n8n 2.40.0 < 2.40.1
