Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another project and send its decrypted secret to an attacker-controlled endpoint. The affected authorization boundary is packages/cli/src/modules/log-streaming.ee/destinations/destination-credentials-access.ts and the credential:read scope. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized credential disclosure
Action: Patch
AI Analysis

Impact

The vulnerability in n8n allows a log streaming event destination to decrypt any generic HTTP credential it references without checking ownership. As a result, a user with a custom global role that includes Log Streaming scopes can point the destination at credentials from other projects and have the plaintext secret sent to an attacker‑controlled endpoint, leading to confidential credential leakage and potential compromise of downstream services.

Affected Systems

n8n – the open source workflow automation platform from n8n-io. Versions prior to 1.123.76, 2.37.7, and 2.38.2 are impacted. Any installation running those releases with a global role that grants Log Streaming permissions is at risk.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the KEV catalog, so the likelihood of widespread exploitation is unclear. However, the description implies that an attacker can exploit the flaw once a custom global role with Log Streaming scopes exists, enabling straightforward credential theft. The attack vector is inferred to be through the Log Streaming destination mechanism within the application code, requiring that the attacker can create or manipulate such a role.

Generated by OpenCVE AI on September 9, 2026 at 08:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to at least version 1.123.76, 2.37.7, or 2.38.2, where the ownership check is enforced.
  • If an upgrade is not immediately possible, remove Log Streaming scopes from any global role that can assign a log streaming event destination, or restrict log streaming to project‑specific roles only.
  • Verify that no credentials are being exposed by reviewing credential usage logs and ensuring that only trusted projects reference external HTTP credentials.

Generated by OpenCVE AI on September 9, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pq6c-vh67-xpm3 n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
History

Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another project and send its decrypted secret to an attacker-controlled endpoint. The affected authorization boundary is packages/cli/src/modules/log-streaming.ee/destinations/destination-credentials-access.ts and the credential:read scope. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T16:04:06.689Z

Reserved: 2026-09-08T16:44:23.781Z

Link: CVE-2026-86993

cve-icon Vulnrichment

Updated: 2026-09-09T15:49:57.523Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:17.810

Modified: 2026-09-10T21:02:49.697

Link: CVE-2026-86993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:14Z

Weaknesses