Credential Verification Flaw in n8n Workflow Automation Platform
CVE-2026-86074

5.9MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86074?

The n8n workflow automation platform, an open-source tool, contains a vulnerability in the Instance AI credential setup flow. This flaw allows an attacker to inject a malicious URL that bypasses origin checks, potentially leading to unauthorized authenticated requests or redirects to unintended origins. This issue affects n8n versions prior to 2.37.7 and 2.38.2 and has been addressed in the newer releases.

Affected Version(s)

n8n < 2.37.7 < 2.37.7

n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.