CVE-2026-85166: n8n

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/updating a workflow via the REST API, Public API, or MCP, can persist a node referencing a credential they do not own. When the workflow is later executed under an identity that holds the credential, the inline sub-workflow resolves the secret and can send it to an attacker-controlled endpoint, resulting in credential exfiltration.

Affected products

  • n8n n8n: before 2.35.4 (fixed in 2.35.4); from 2.36.0, before 2.36.2 (fixed in 2.36.2)

Published 2026-09-03. Last modified 2026-09-10.