Log Streaming Credential Exposure in n8n Automation Platform
CVE-2026-86993

5.9MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86993?

The n8n automation platform contains a vulnerability that allows users with custom global roles to access and decrypt HTTP credentials belonging to other projects. This occurs without proper ownership verification, enabling the potential for sensitive information to be sent to attacker-controlled endpoints. The issue is located in the Log Streaming event destination feature, specifically affecting the credential:read scope. Users are advised to update to the latest versions, 1.123.76, 2.37.7, or 2.38.2, to mitigate this risk.

Affected Version(s)

n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2

n8n >= 2.0.0, < 2.37.7 < 2.0.0, 2.37.7

n8n < 1.123.76 < 1.123.76

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.