Authentication Vulnerability in n8n Workflow Automation Tool by n8n
CVE-2026-72772
8.9HIGH
What is CVE-2026-72772?
The n8n Workflow Automation Tool is impacted by an authentication bypass vulnerability due to improper verification of email claims during the Token Exchange Embed Login feature. This flaw allows unauthorized users to gain full control over accounts if they possess a valid incoming token linked to a trusted key. The vulnerability arises when the email associated with a token is not adequately verified, permitting attackers to impersonate existing users. This issue primarily affects environments with enabled embed login features and configured trusted key sources. Remediation involves updating to the latest versions of n8n to mitigate associated risks.
Affected Version(s)
n8n 0 < 2.32.1
n8n 0 < 2.31.5
n8n 2.32.1
