Description
n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.
Published: 2026-10-01
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: Credential Tampering
Action: Upgrade
AI Analysis

Impact

n8n versions released before 1.123.80 allow an attacker who can edit a shared workflow to tamper with credentials by creating duplicate node identifiers. The workflow credential tamper guard is bypassed when an attacker supplies a node name that differs from its ID, enabling the attacker to retain the victim’s credentials and direct them to a host controlled by the attacker, thereby revealing sensitive secrets.

Affected Systems

The vulnerability affects all installations of n8n-io:n8n up to, but not including, version 1.123.80. Any instance running a workflow that permits editor access from other users is potentially impacted.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate impact, and the EPSS score is not available, so the probability of public exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers would need editor-level permissions on a shared workflow and would exploit the mismatch between node IDs and names; the likelihood of exploitation depends on the number of shared workflows with insufficient permission controls.

Generated by OpenCVE AI on October 1, 2026 at 14:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update n8n to version 1.123.80 or later, which includes a patch that enforces the credential tamper guard for all node IDs.
  • Audit existing workflows to identify and correct duplicate node IDs, ensuring each ID uniquely matches its node name.
  • Restrict or review editor permissions for shared workflows so that only trusted users can modify workflow nodes, thereby reducing the attack surface.

Generated by OpenCVE AI on October 1, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.
Title n8n before 1.123.80 Credential Tampering via Duplicate Node IDs
First Time appeared N8n
N8n n8n
Weaknesses CWE-639
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:41:54.215Z

Reserved: 2026-09-30T10:52:32.248Z

Link: CVE-2026-103247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:18.070

Modified: 2026-10-01T11:17:18.207

Link: CVE-2026-103247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key