PT-2026-50173 · N8N · N8N

·

CVE-2026-54307

·

Published

2026-06-16

·

Updated

2026-07-16

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.55 n8n versions prior to 2.25.7 n8n versions prior to 2.26.2
Description An open source workflow automation platform contains an issue where a member-level user with editor access to a shared workflow can reference credentials they do not own through specific public API endpoints. This occurs because credential ownership checks were only partially enforced, allowing cross-user credential access. The issue affects instances where workflow sharing is enabled and at least one workflow is shared with a member-level user as an Editor.
Recommendations Update to version 1.123.55 or later. Update to version 2.25.7 or later. Update to version 2.26.2 or later. Restrict workflow sharing to fully trusted users only. Audit shared workflows for unexpected credential references or recent modifications.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54307
GHSA-PMQW-72CG-WX85

Affected Products

N8N