Dynamic Credentials Feature Vulnerability in n8n Automation Platform
CVE-2026-54305

8.9HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54305?

A security vulnerability exists in the Dynamic Credentials feature of n8n, an open-source workflow automation platform. Versions before 1.123.55, 2.25.7, and 2.26.2 allow an authenticated user to exploit three exposed EE endpoints without proper resource ownership or scope checks. This flaw lets the attacker enumerate sensitive credential information associated with private workflows and initiate unauthorized OAuth flows, leading to the potential overwrite of user tokens. Moreover, they could revoke credentials from other users, breaking affected workflows and allowing data exfiltration to external services under their control. The issue has been resolved in the specified updated versions.

Affected Version(s)

n8n < 1.123.55 < 1.123.55

n8n >= 2.0.0-rc.0, < 2.25.7 < 2.0.0-rc.0, 2.25.7

n8n >= 2.26.0, < 2.26.2 < 2.26.0, 2.26.2

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.