n8n Cross-Tenant Credential Takeover Vulnerability (CVE-2026-54305) — CRITICAL Severity

Understanding the n8n Cross-Tenant Credential Takeover Vulnerability

n8n, a popular open-source workflow automation platform, has identified a critical security flaw that could allow unauthorized access and manipulation of user credentials. This vulnerability, tracked as CVE-2026-54305, primarily affects Enterprise instances of n8n where the Dynamic Credentials feature is active.

In simple terms, certain parts of the Dynamic Credentials feature did not properly check who owned or had permission to access specific workflows and credentials. This oversight meant that any authenticated user on an n8n Enterprise instance could potentially view details about other users’ private credentials, initiate actions to steal or overwrite their authentication tokens (like OAuth tokens), or even completely revoke those tokens. Imagine an attacker gaining control over your automated workflows or disrupting critical integrations without your knowledge.

If an attacker successfully hijacks a credential, any workflows relying on it would then operate under the attacker’s control. This could lead to sensitive data being sent to external services controlled by the attacker, effectively giving them a persistent way to take over your integrations. Alternatively, revoking tokens could simply break essential workflows, causing significant operational disruption.

CVE Details

  • Product: n8n
  • Published: June 23, 2026
  • Severity: CRITICAL
  • Status: Analyzed

Affected Products

This vulnerability impacts n8n Enterprise instances using the Dynamic Credentials feature. Specifically, affected versions include:

  • n8n versions prior to 1.123.55
  • n8n versions prior to 2.25.7
  • n8n versions prior to 2.26.2

Current Status

The vulnerability has been thoroughly analyzed by n8n, and patches have been released to address the issue. It is crucial for affected users to take immediate action to secure their n8n instances.

Severity Level

Rated as CRITICAL with a CVSS score of 9.9 out of 10, this vulnerability poses a significant risk. A critical rating indicates a high potential for widespread impact, including unauthorized data breaches, complete takeover of integrations, and severe disruption to automated workflows. The ease of exploitation by an authenticated user with low privileges contributes to its high severity.

Possible Solutions

To protect your n8n instance from this critical vulnerability, the primary solution is to upgrade to a patched version immediately. The issue has been fixed in the following releases:

  • n8n version 1.123.55 and later
  • n8n version 2.25.7 and later
  • n8n version 2.26.2 and later

If an immediate upgrade is not feasible, n8n has suggested a couple of temporary mitigation steps for Enterprise administrators:

  • Restrict Access: Ensure that your n8n instance is only accessible to users you fully trust.
  • Disable Dynamic Credentials: If the Dynamic Credentials feature is not actively being used, consider disabling it. This can typically be done by unsetting the environment variable N8N_ENV_FEAT_DYNAMIC_CREDENTIALS. Please note that these are temporary workarounds and do not fully eliminate the risk; a proper upgrade remains the recommended long-term solution.

References

https://github.com/n8n-io/n8n/security/advisories/GHSA-2j5h-858j-5mpf

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.