CVE-2026-103252: n8n-Io n8n

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled hosts for exfiltration.

Affected products

  • n8n-Io n8n: before 1.123.80 (fixed in 1.123.80); from 2.0.0, before 2.39.6 (fixed in 2.39.6); from 2.40.0, before 2.40.1 (fixed in 2.40.1)

Published 2026-10-01. Last modified 2026-10-01.