Authentication Vulnerability in n8n Workflow Automation Tool by n8n
CVE-2026-72772

8.9HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72772?

The n8n Workflow Automation Tool is impacted by an authentication bypass vulnerability due to improper verification of email claims during the Token Exchange Embed Login feature. This flaw allows unauthorized users to gain full control over accounts if they possess a valid incoming token linked to a trusted key. The vulnerability arises when the email associated with a token is not adequately verified, permitting attackers to impersonate existing users. This issue primarily affects environments with enabled embed login features and configured trusted key sources. Remediation involves updating to the latest versions of n8n to mitigate associated risks.

Affected Version(s)

n8n 0 < 2.32.1

n8n 0 < 2.31.5

n8n 2.32.1

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.