Description
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects.
Published: 2026-08-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Credential Access
Action: Upgrade
AI Analysis

Impact

n8n versions prior to 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when the authentication type is set to an expression. The flaw allows an attacker who has a valid MCP Bearer API key and knows a target credential ID to persist unauthorized cross‑project credential references on workflows that belong to other projects. This results in the attacker gaining access to credentials that were not intended for those projects, violating confidentiality and potentially enabling further exploitation.

Affected Systems

n8n-io:n8n, all versions before 2.34.1

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker requires possession of a valid MCP Bearer API key, which is typically limited to trusted users, but once obtained the bypass can be exploited within the same system to reference credentials across projects.

Generated by OpenCVE AI on August 20, 2026 at 22:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to n8n 2.34.1 or later to eliminate the credential validation bypass.
  • If immediate upgrade is not possible, restrict the use of MCP Bearer API keys to a minimal set of authorized personnel and revoke any keys that may have been exposed.
  • Disable or audit expressions used in the authentication type within the MCP create_workflow_from_code tool to prevent the bypass condition.
  • Regularly review workflows for cross‑project credential references and remove any that appear unauthorized.

Generated by OpenCVE AI on August 20, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:2.34.0:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects.
Title n8n before 2.34.1 Cross-Project Credential Access via MCP
First Time appeared N8n
N8n n8n
Weaknesses CWE-639
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-25T14:27:51.234Z

Reserved: 2026-08-20T10:51:39.783Z

Link: CVE-2026-77073

cve-icon Vulnrichment

Updated: 2026-08-25T14:27:44.769Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T12:16:38.613

Modified: 2026-09-01T19:14:15.463

Link: CVE-2026-77073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:09Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key