PT-2026-56817 · N8N · N8N
CVE-2026-59208
·
Published
2026-07-09
·
Updated
2026-08-26
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 2.27.4
n8n versions 2.28.0 through 2.28.0
Description
Instances configured with multiple trusted token-exchange issuers resolve external identities to local accounts using only the
sub claim of the JSON Web Token (JWT) and ignore the iss claim. This allows an attacker possessing a valid token from one trusted issuer with a sub value matching a victim under a different issuer to authenticate as that victim.Recommendations
Update to version 2.27.4.
Update to version 2.28.1.
Exploit
Fix
Origin Validation Error
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
N8N