PT-2026-78929 · N8N · N8N

·

CVE-2026-77073

·

Published

2026-08-20

·

Updated

2026-09-01

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.34.1
Description A credential validation bypass exists in the MCP create workflow from code tool when the authentication type is configured as an expression. An attacker possessing a valid MCP Bearer API key and a target credential ID can establish unauthorized cross-project credential references on workflows located in different projects.
Recommendations Update n8n to version 2.34.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77073
GHSA-VFRJ-582Q-MVCP

Affected Products

N8N