Authorization Flaw in n8n Workflow Automation Platform
CVE-2026-42226

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
4 May 2026

What is CVE-2026-42226?

A security vulnerability in the n8n workflow automation platform prior to specific versions allows authenticated users to exploit dynamic-node-parameters endpoints. These endpoints fail to verify the legitimacy of credential references supplied in requests, enabling the unauthorized use of another user’s credentials. This can result in exfiltration of sensitive API keys as attackers can manipulate the backend to authenticate against their infrastructure, thereby bypassing intended authorization controls. The issue affects any node type resolving credentials dynamically and has been remedied in the latest versions of n8n.

Affected Version(s)

n8n < 1.123.33 < 1.123.33

n8n >= 2.17.0, < 2.17.5 < 2.17.0, 2.17.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.