Junglewise Threat Intelligence

CVE-2026-33663: n8n Community Edition credential theft via name-based resolution bypass

CVE-2026-33663 · Severity: low · CVSS 3.1 · Published 2026-03-25

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is an open-source workflow automation platform that manages credentials and integrations. In the Community Edition, a member-role user can steal plaintext secrets (API keys, passwords) from generic HTTP credentials belonging to other users by exploiting an authorization flaw that allows access to credentials without ownership verification. This enables attackers with basic user accounts to extract sensitive credentials used for external service integrations.

Technical details

The vulnerability is an authorization bypass (CWE-639) affecting n8n's credential resolution pipeline. An authenticated user with global:member role can exploit two chained flaws: a name-based credential resolution path that fails to enforce ownership/project scope, and a permission checker bypass that skips validation for generic HTTP credential types (httpBasicAuth, httpHeaderAuth, httpQueryAuth). By combining these flaws, an attacker can resolve another user's credential ID and execute workflows that decrypt and use those credentials without authorization. Network attack vector requires authentication but no additional user interaction. Native integration credential types (Slack, OpenAI, PostgreSQL) are unaffected. Enterprise Edition is not vulnerable due to additional permission gates. Patches are available in versions 1.123.27, 2.13.3, and 2.14.1.

Affected products

  • n8n n8n < 1.123.27; 2.0.0-rc.0 to < 2.13.3; 2.14.0

Timeline

  • 2026-03-25: disclosed
  • 2026-03-25: patched: Fixed in versions 1.123.27, 2.13.3, and 2.14.1

References

Related threats