CVE-2026-103252: Authorization Bypass Through User-Controlled Key in n8n-io n8n
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled hosts for exfiltration.
AI Analysis
Technical Summary
CVE-2026-103252 is an authorization bypass vulnerability in n8n's credential test endpoint affecting versions <1.123.80, >=2.0.0 <2.39.6, and >=2.40.0 <2.40.1. The vulnerability arises because the endpoint resolves project-scoped variables without verifying if the caller has access rights to the specified project. Attackers can exploit this by specifying arbitrary project IDs in requests, causing sensitive variables to be interpolated and sent to attacker-controlled hosts, potentially leaking confidential information.
Potential Impact
An attacker with limited privileges can bypass authorization controls to access sensitive project-scoped variables. This can result in unauthorized disclosure of sensitive credentials or configuration data by exfiltrating them to attacker-controlled endpoints. The vulnerability has a CVSS 4.0 base score of 7.1, indicating high severity due to network attack vector, low attack complexity, and high impact on confidentiality.
Mitigation Recommendations
Users should upgrade n8n to versions 1.123.80 or later, 2.39.6 or later, or 2.40.1 or later where this vulnerability is fixed. Since this is a software vulnerability with fixed versions available, applying the official patches is the recommended remediation. No vendor advisory content was provided to indicate otherwise.
CVE-2026-103252: Authorization Bypass Through User-Controlled Key in n8n-io n8n
Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled hosts for exfiltration.
CVSS v4.0
Score 7.1high
Affected software
n8n-io
n8n
pkg:github/n8n-io/n8nRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103252 is an authorization bypass vulnerability in n8n's credential test endpoint affecting versions <1.123.80, >=2.0.0 <2.39.6, and >=2.40.0 <2.40.1. The vulnerability arises because the endpoint resolves project-scoped variables without verifying if the caller has access rights to the specified project. Attackers can exploit this by specifying arbitrary project IDs in requests, causing sensitive variables to be interpolated and sent to attacker-controlled hosts, potentially leaking confidential information.
Potential Impact
An attacker with limited privileges can bypass authorization controls to access sensitive project-scoped variables. This can result in unauthorized disclosure of sensitive credentials or configuration data by exfiltrating them to attacker-controlled endpoints. The vulnerability has a CVSS 4.0 base score of 7.1, indicating high severity due to network attack vector, low attack complexity, and high impact on confidentiality.
Mitigation Recommendations
Users should upgrade n8n to versions 1.123.80 or later, 2.39.6 or later, or 2.40.1 or later where this vulnerability is fixed. Since this is a software vulnerability with fixed versions available, applying the official patches is the recommended remediation. No vendor advisory content was provided to indicate otherwise.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-30T10:52:32.249Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abe7484a43b0b3b89bd10d8
Added to database: 10/01/2026, 14:56:04 UTC
Last enriched: 10/01/2026, 15:15:04 UTC
Last updated: 10/02/2026, 01:04:28 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.