Credential Authorization Bypass in n8n Workflow Automation Tool
CVE-2026-72774
7.1HIGH
What is CVE-2026-72774?
In n8n versions prior to 1.123.67, 2.31.5, and 2.32.1, a credential authorization bypass exists within the HTTP Request node. This vulnerability allows an authenticated user with edit access to a shared workflow to improperly refer to another user's credentials. The flaw occurs because the permission checks do not appropriately verify the resolved credential type, inadvertently permitting access to credentials that the user does not possess permissions for. Malicious exploitation of this weakness requires knowledge of the specific identifier associated with the targeted credential, enabling unauthorized use or extraction of sensitive information.
Affected Version(s)
n8n 0 < 1.123.67
n8n 0 < 2.32.1
n8n 0 < 2.31.5
