PT-2026-70165 · N8N · N8N

·

CVE-2026-72763

·

Published

2026-07-22

·

Updated

2026-09-01

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.67 n8n versions prior to 2.31.5 n8n versions prior to 2.32.1
Description Insufficient validation of credential access occurs when using the Execute Sub-workflow node. The system only validates top-level credentials and fails to check credentials referenced within the inline workflow JSON. A user with Editor access to a shared workflow can reference a target credential ID within the inline JSON to bypass save-time and runtime validation. This allows the user to utilize or exfiltrate credentials from the parent workflow's project context that they are not authorized to access.
Recommendations Update to version 1.123.67 or later. Update to version 2.31.5 or later. Update to version 2.32.1 or later.

Exploit

Fix

Incorrect Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72763
GHSA-CJ9H-QX8G-PQ2G

Affected Products

N8N