PT-2026-84998 · N8N · N8N

·

CVE-2026-85166

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.35.4 n8n versions 2.36.x prior to 2.36.2
Description Insufficient validation of credential references in the inline workflow JSON of nodes that execute inline sub-workflows, such as the Workflow Tool node, allows a shared-workflow editor or any user interacting via the REST API, Public API, or MCP to persist a node referencing a credential they do not own. If the workflow is executed by an identity that possesses the referenced credential, the inline sub-workflow can resolve the secret and transmit it to an external endpoint controlled by an attacker, leading to credential exfiltration.
Recommendations Update n8n to version 2.35.4 or later. Update n8n versions 2.36.x to 2.36.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85166
GHSA-4R56-G65C-FM83

Affected Products

N8N