n8n OpenAI Credential Exposure Vulnerability (CVE-2026-86082) — Medium Severity

Understanding the n8n OpenAI Credential Exposure Vulnerability

A security flaw has been identified in n8n, an open-source platform that helps you automate various workflows. This vulnerability, tracked as CVE-2026-86082, affects the way n8n’s OpenAI Chat Model node handles credentials. Simply put, it failed to properly restrict which internet addresses (domains) could receive your OpenAI API credentials when using the model-search dropdown. This could potentially allow a bad actor with workflow editing access to send your sensitive OpenAI API credentials to a server they control.

CVE Details

  • Product: n8n
  • Published Date: September 8, 2026
  • Severity: Medium
  • Status: Analyzed

Affected Products

This vulnerability impacts versions of n8n prior to the following:

  • n8n 1.123.76
  • n8n 2.37.7
  • n8n 2.38.2

If you are running any n8n version older than those listed, your installation might be at risk.

Current Status

The vulnerability status is “Analyzed”, meaning it has been thoroughly investigated and understood by the relevant parties. Fixes are available.

Severity Level

The severity of this issue is rated as MEDIUM. A medium severity rating means that while the vulnerability could be exploited, it might require specific conditions or user interaction. In this case, an attacker would need to have workflow editor access within the n8n platform to exploit this flaw. However, if exploited, it could lead to the exposure of your OpenAI API credentials, which are sensitive and should be protected.

Possible Solutions

The good news is that n8n has already released patches to address this vulnerability. To secure your n8n installation, it is crucial to update to one of the following versions or newer:

  • n8n version 1.123.76
  • n8n version 2.37.7
  • n8n version 2.38.2

Always ensure your software is up-to-date to protect against known security vulnerabilities.

References

https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.76

https://github.com/n8n-io/n8n/releases/tag/n8n@2.37.7

https://github.com/n8n-io/n8n/releases/tag/n8n@2.38.2

https://github.com/n8n-io/n8n/security/advisories/GHSA-34ff-336r-5q23

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.