CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-54307

Critical · CVSS 9.6

n8n — Improper Authorization / Cross-User Credential Access (CWE-863)

CVSS
9.6
nvd
EPSS
KEV
No
Class
other
CWE-863

Description

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced partially leading to cross-user credential access. This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.

Search profile — drives PoC discovery

Symbols credential ownership checkpublic API endpointsworkflow sharingeditor accessshared workflowmember-level usercross-user credential access
Keywords CVE-2026-54307n8n credential accessn8n authorization bypassn8n workflow sharing exploitGHSA-pmqw-72cg-wx85n8n public API credentialn8n editor credential bypassn8n member credential escalation
Versions: < 1.123.55, < 2.25.7, < 2.26.2

References

Status: enriched · ingested 2026-06-26T06:00:38.000Z · profiled 2026-07-01T18:30:14.000Z