Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with Editor access to a shared workflow (when workflow sharing is enabled) who knows a target credential's ID can reference that credential in the inline JSON; it passes save-time and runtime validation and resolves in the parent workflow's project context, allowing the attacker to use or exfiltrate credentials they are not permitted to access. | |
| Title | n8n before 1.123.67 Credential Exfiltration via Sub-Workflow | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T18:01:18.334Z
Reserved: 2026-08-10T15:06:16.417Z
Link: CVE-2026-72763
No data.
Status : Received
Published: 2026-08-11T13:19:06.367
Modified: 2026-08-11T18:18:24.477
Link: CVE-2026-72763
No data.
OpenCVE Enrichment
No data.