PT-2026-70174 · N8N · N8N
CVE-2026-72772
·
Published
2026-07-22
·
Updated
2026-08-11
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 2.32.1
n8n versions prior to 2.31.5
Description
The Token Exchange Embed Login feature allows for account takeover. The issue occurs when a validly-signed incoming token is matched to a local account via its email claim, but the service fails to verify if the email claim was verified or if the trusted key's permitted role ceiling covers that account. Consequently, an attacker who obtains a token accepted by a configured trusted key, such as one from a trusted issuer that emits unverified email addresses, can authenticate as any existing user and gain full account control. This issue only affects instances where the embed login feature is enabled and at least one trusted key source is configured.
Recommendations
Update to version 2.32.1 or later.
Update to version 2.31.5 or later.
As a temporary mitigation, disable the embed login feature or remove configured trusted key sources.
Exploit
Fix
Incorrect Authorization
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
N8N