CVE-2026-103256
Deferred
Deferred - Pending Action
Credentials Leak in n8n via Wekan and Baserow
Vulnerability report for CVE-2026-103256, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: VulnCheck
Description
Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| n8n | n8n | to 2.39.6 (exc) |
| n8n | n8n | to 2.40.0 (exc) |
| n8n | n8n | to 2.40.1 (exc) |
| wekan | wekan | * |
| baserow | baserow | * |
| n8n | n8n | to 2.39.6|end_excluding=2.40.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |