PT-2026-70174 · N8N · N8N

CVE-2026-72772

·

Published

2026-07-22

·

Updated

2026-08-11

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.32.1 n8n versions prior to 2.31.5
Description The Token Exchange Embed Login feature allows for account takeover. The issue occurs when a validly-signed incoming token is matched to a local account via its email claim, but the service fails to verify if the email claim was verified or if the trusted key's permitted role ceiling covers that account. Consequently, an attacker who obtains a token accepted by a configured trusted key, such as one from a trusted issuer that emits unverified email addresses, can authenticate as any existing user and gain full account control. This issue only affects instances where the embed login feature is enabled and at least one trusted key source is configured.
Recommendations Update to version 2.32.1 or later. Update to version 2.31.5 or later. As a temporary mitigation, disable the embed login feature or remove configured trusted key sources.

Exploit

Fix

Incorrect Authorization

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72772
GHSA-8342-988Q-86CR

Affected Products

N8N