Credential Exfiltration Vulnerability in n8n Workflow Tool by n8n.io
CVE-2026-85166

7.2HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85166?

The vulnerability in n8n allows for credential exfiltration through improper validation of credential references in inline workflows. Users can create or update workflows using the REST API or Public API, which may inadvertently reference credentials they do not own. When these workflows are executed in a context that has access to those credentials, sensitive information can be sent to potentially malicious endpoints, exposing crucial user secrets.

Affected Version(s)

n8n 0 < 2.36.2

n8n 0 < 2.35.4

n8n 2.36.2

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Solidscripting
.