Session Token Leakage in n8n's Dynamic Credentials Functionality
CVE-2026-103259

8.5HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103259?

A session token leakage vulnerability exists in n8n affecting versions prior to 2.39.6 and versions 2.40.0 before 2.40.1. This issue arises during the account connection flow at the Dynamic Credentials endpoints, where attackers with resolver registration capabilities can exploit a fallback resolver set to a maliciously controlled endpoint. As a result, they can capture collaborators' session tokens, leading to unauthorized access to sensitive credentials.

Affected Version(s)

n8n 0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nlgbao1340
.