CVE-2026-103259
Deferred Deferred - Pending Action

Session Token Leakage in n8n Workflow Automation

Vulnerability report for CVE-2026-103259, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
n8n n8n to 2.39.6 (exc)
n8n n8n to 2.40.0 (exc)
n8n n8n to 2.40.1 (exc)
n8n-io n8n to 2.39.6 (exc)
n8n-io n8n to 2.40.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects n8n versions before 2.39.6 and 2.40.0 before 2.40.1. It involves a session token leakage in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.

Impact Analysis

This vulnerability can lead to unauthorized access to credentials and sensitive data. Attackers may gain control over accounts, manipulate workflows, or exfiltrate confidential information. The impact includes compromised confidentiality, integrity, and availability of systems using affected n8n versions.

Compliance Impact

This vulnerability can lead to data breaches, violating GDPR and HIPAA requirements for data protection and access controls. Organizations may face legal penalties, reputational damage, and loss of trust due to unauthorized access to personal or health information.

Mitigation Strategies
  • Upgrade n8n to version 2.39.6 or later, or 2.40.1 or later to patch the vulnerability.
  • Disable the Dynamic Credentials module if not required.
  • Restrict access to the n8n instance to trusted users only.
  • Audit custom global roles and remove unnecessary permissions.
  • Review and remove any suspicious or unauthorized registered resolvers.
  • Rotate all session tokens and credentials to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103259. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart