CVE-2026-72771: Incorrect Authorization in n8n-io n8n
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
AI Analysis
Technical Summary
CVE-2026-72771 is an incorrect authorization vulnerability in n8n versions before 2.32.1. The flaw arises because the Allowed HTTP Request Domains allowlist is not properly enforced in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. This enables low-privileged workflow editors, who only have use-only access to shared credentials, to redirect HTTP requests to attacker-controlled hosts. Consequently, attackers can exfiltrate credential secrets and reuse them against underlying services, potentially compromising those services.
Potential Impact
An attacker with low-privileged workflow editor access can bypass domain restrictions and redirect requests to malicious hosts, leading to credential exfiltration. This can result in unauthorized access to underlying services that rely on the stolen credentials. The vulnerability poses a high risk due to the potential for credential theft and misuse.
Mitigation Recommendations
A fix is available in n8n version 2.32.1 that enforces the Allowed HTTP Request Domains allowlist correctly. Users should upgrade to version 2.32.1 or later to remediate this vulnerability. Since no official vendor advisory or patch link is provided, verify the patch status with the vendor or official n8n release notes to confirm remediation.
CVE-2026-72771: Incorrect Authorization in n8n-io n8n
Description
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
CVSS v4.0
Score 7.1high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-72771 is an incorrect authorization vulnerability in n8n versions before 2.32.1. The flaw arises because the Allowed HTTP Request Domains allowlist is not properly enforced in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. This enables low-privileged workflow editors, who only have use-only access to shared credentials, to redirect HTTP requests to attacker-controlled hosts. Consequently, attackers can exfiltrate credential secrets and reuse them against underlying services, potentially compromising those services.
Potential Impact
An attacker with low-privileged workflow editor access can bypass domain restrictions and redirect requests to malicious hosts, leading to credential exfiltration. This can result in unauthorized access to underlying services that rely on the stolen credentials. The vulnerability poses a high risk due to the potential for credential theft and misuse.
Mitigation Recommendations
A fix is available in n8n version 2.32.1 that enforces the Allowed HTTP Request Domains allowlist correctly. Users should upgrade to version 2.32.1 or later to remediate this vulnerability. Since no official vendor advisory or patch link is provided, verify the patch status with the vendor or official n8n release notes to confirm remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T15:06:16.417Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7b151ebf8831d539b28d4f
Added to database: 08/11/2026, 12:27:10 UTC
Last enriched: 08/11/2026, 12:41:56 UTC
Last updated: 08/11/2026, 13:20:32 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.