Dynamic Credentials Feature Vulnerability in n8n Automation Platform
CVE-2026-54305
What is CVE-2026-54305?
A security vulnerability exists in the Dynamic Credentials feature of n8n, an open-source workflow automation platform. Versions before 1.123.55, 2.25.7, and 2.26.2 allow an authenticated user to exploit three exposed EE endpoints without proper resource ownership or scope checks. This flaw lets the attacker enumerate sensitive credential information associated with private workflows and initiate unauthorized OAuth flows, leading to the potential overwrite of user tokens. Moreover, they could revoke credentials from other users, breaking affected workflows and allowing data exfiltration to external services under their control. The issue has been resolved in the specified updated versions.
Affected Version(s)
n8n < 1.123.55 < 1.123.55
n8n >= 2.0.0-rc.0, < 2.25.7 < 2.0.0-rc.0, 2.25.7
n8n >= 2.26.0, < 2.26.2 < 2.26.0, 2.26.2
