Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Credentials Leak
Action: Patch
AI Analysis

Impact

The vulnerability allows the circumvention of the preAuthentication Hook’s host validation, enabling an attacker with credential update rights to modify the host entry so that stored username‑password credentials for Wekan and Baserow are transmitted in cleartext to an arbitrary, attacker‑controlled host. The result is a leak of the credentials that can be used to compromise services that rely on them, threatening account confidentiality and potentially the integrity of downstream systems. The flaw is a credential storage confidentiality issue (CWE‑522).

Affected Systems

The affected product is n8n, versions before 2.39.6 and before 2.40.1 for the 2.40.x line. All installations using the preAuthentication Hook and hosting credentials for Wekan or Baserow are vulnerable unless upgraded to the specified patched releases.

Risk and Exploitability

The CVSS score of 7.1 indicates a high risk with significant impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower public exploitation probability but a still serious threat. Attackers need existing credential‑update permissions to exploit the flaw; once permissions are available, they can redirect credentials to any host, making the flaw an effective tool for credential exfiltration.

Generated by OpenCVE AI on October 1, 2026 at 14:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade n8n to version 2.39.6 or later, or to 2.40.1 or later for the 2.40.x line.
  • If an upgrade is not immediately possible, restrict credential update rights to a minimum set of trusted administrators to reduce the attack surface.
  • After updating or restricting permissions, revoke all existing Wekan and Baserow credentials and regenerate them to prevent the use of potentially leaked passwords.

Generated by OpenCVE AI on October 1, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.
Title n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook
First Time appeared N8n
N8n n8n
Weaknesses CWE-522
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:28:13.266Z

Reserved: 2026-09-30T10:55:39.869Z

Link: CVE-2026-103256

cve-icon Vulnrichment

Updated: 2026-10-01T13:27:59.449Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:19.913

Modified: 2026-10-01T14:17:22.170

Link: CVE-2026-103256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials