Session Token Leakage in n8n's Dynamic Credentials Functionality
CVE-2026-103259
8.5HIGH
What is CVE-2026-103259?
A session token leakage vulnerability exists in n8n affecting versions prior to 2.39.6 and versions 2.40.0 before 2.40.1. This issue arises during the account connection flow at the Dynamic Credentials endpoints, where attackers with resolver registration capabilities can exploit a fallback resolver set to a maliciously controlled endpoint. As a result, they can capture collaborators' session tokens, leading to unauthorized access to sensitive credentials.
Affected Version(s)
n8n 0 < 2.39.6
n8n 2.40.0 < 2.40.1
