Credential Validation Bypass in n8n Versions by n8n-io
CVE-2026-77073

5.3MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77073?

n8n versions prior to 2.34.1 are susceptible to a vulnerability that allows a credential validation bypass in the MCP create_workflow_from_code tool when the authentication type is configured as an expression. If an attacker has a valid MCP Bearer API key and knows the target credential ID, they can exploit this weakness to maintain unauthorized cross-project credential references within workflows across different projects, risking data integrity and security.

Affected Version(s)

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

n8n 2.34.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vonypeto
.