PT-2026-60132 · N8N · N8N

·

CVE-2026-59259

·

Published

2026-07-15

·

Updated

2026-07-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.61 n8n versions prior to 2.27.4 n8n versions prior to 2.28.1
Description A permission bypass exists in external secrets handling due to a mismatch between the static validation check and the runtime expression engine. This occurs in instances where an external secrets provider is configured and Advanced Permissions are enabled. An authenticated user possessing credential create or update permissions, but lacking the externalSecret:list scope, can embed external secret references into credentials using forms that bypass static validation. These references are resolved during workflow execution, allowing the user to access secret values they are not authorized to view.
Recommendations Update to version 1.123.61 or later. Update to version 2.27.4 or later. Update to version 2.28.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59259
GHSA-JP7M-XCGX-57QM
GHSA-Q6MX-QVHP-FQMG

Affected Products

N8N