Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled hosts for exfiltration.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Information Disclosure via Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authorization bypass in the credential test endpoint that permits an attacker to specify an arbitrary project ID in the request body. By doing so, the endpoint resolves project‑scoped variables and forces them to be sent to a host specified by the attacker. This allows the exfiltration of sensitive data such as passwords or API keys, representing a clear confidentiality breach. The weakness is captured by CWE‑639, a classic information disclosure issue.

Affected Systems

It affects all installations of n8n running any version before 1.123.80, including 2.0.0 through 2.39.5, and the 2.40.0 series up to 2.40.0 inclusive. Version 2.40.1 and later are known to contain the fix.

Risk and Exploitability

The CVSS score of 7.1 marks it as a high‑impact vulnerability, yet no EPSS data is available and it is not listed in CISA's KEV catalog, suggesting no widespread exploitation yet. Likely, an attacker must be able to send crafted HTTP requests to the credential test endpoint, either internally or externally if the API is exposed. Successful exploitation results in disclosure of project‑specific secrets, which could lead to broader compromise of connected services. Given the severity and the potential for data leakage, immediate remediation is recommended.

Generated by OpenCVE AI on October 1, 2026 at 14:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to n8n 1.123.80 or later, or to n8n 2.39.6 or 2.40.1 and newer, to apply the vendor fix.
  • If an upgrade cannot be performed immediately, restrict or firewall access to the credential test API endpoint so that only trusted administrators can invoke it.
  • Continuously monitor API logs for unexpected credential test requests or data exfiltration patterns, and investigate suspicious activity promptly.

Generated by OpenCVE AI on October 1, 2026 at 14:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled hosts for exfiltration.
Title n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential Test Endpoint
First Time appeared N8n
N8n n8n
Weaknesses CWE-639
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:27:33.545Z

Reserved: 2026-09-30T10:52:32.249Z

Link: CVE-2026-103252

cve-icon Vulnrichment

Updated: 2026-10-01T13:27:29.843Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:19.160

Modified: 2026-10-01T14:17:21.020

Link: CVE-2026-103252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key