Credentials Leak Vulnerability in n8n by n8n-io
CVE-2026-103256

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103256?

n8n prior to version 2.39.6 and versions 2.40.0 leading up to 2.40.1 are susceptible to a credential leak vulnerability. This issue allows unencrypted username-and-password credentials associated with Wekan and Baserow to be sent to unvalidated hosts. Attackers who possess permissions to update credentials can manipulate the host field, facilitating the capture of accounts' passwords by redirecting them to arbitrary hosts, thus evading any domain validation controls that may be in place.

Affected Version(s)

n8n 0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nlgbao1340
.