CVE-2026-103259
n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials
CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.
| CWE | CWE-863 |
| Vendor | n8n-io |
| Product | n8n |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for n8n-io n8n
Be the first to know when new high vulnerabilities affecting n8n-io n8n are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
n8n-io / n8n
0 < 2.39.6 2.40.0 < 2.40.1
References
Credits
๐ nlgbao1340