CVE-2026-103256
Deferred Deferred - Pending Action

Credentials Leak in n8n via Wekan and Baserow

Vulnerability report for CVE-2026-103256, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
n8n n8n to 2.39.6 (exc)
n8n n8n to 2.40.0 (exc)
n8n n8n to 2.40.1 (exc)
wekan wekan *
baserow baserow *
n8n n8n to 2.39.6|end_excluding=2.40.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects n8n versions before 2.39.6 and 2.40.0 before 2.40.1. It involves a credentials leak in Wekan and Baserow integrations where unencrypted passwords are sent to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary locations, bypassing domain validation controls.

Detection Guidance

To detect this vulnerability, monitor outbound network traffic for unencrypted password transmissions to unexpected hosts. Check n8n logs for credential updates with modified host fields in Wekan or Baserow integrations. Review network traffic for plaintext passwords sent to arbitrary domains.

Impact Analysis

Attackers could steal plaintext passwords without leaving traces in execution logs. This could lead to unauthorized access to accounts, data breaches, or further exploitation of compromised systems. Users with credential update rights are particularly at risk.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance penalties, legal consequences, and reputational damage due to data breaches resulting from credential theft.

Mitigation Strategies

Immediately upgrade n8n to versions 2.40.1 or 2.39.6 or later. Restrict instance access to trusted users. Audit custom roles to limit credential update permissions. Review all credential fields for unexpected host values. Monitor outbound network traffic for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103256. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart