Executive brief
n8n is a workflow automation platform that supports LDAP (directory) authentication for enterprise environments. When LDAP is enabled, a flaw in account linking allows authenticated LDAP users who can modify their email address in the directory to take over any other account by setting their email to match another user's—including administrators. Once linked, this access persists permanently even if the attacker reverts their email, enabling full account takeover.
Technical details
The vulnerability is an improper authentication flaw (CWE-287) in n8n's LDAP account linking logic. When LDAP authentication is active, n8n automatically links an LDAP identity to an existing local account if the LDAP email attribute matches the account's registered email. An authenticated LDAP user with the ability to modify their own email attribute in the LDAP directory can exploit this by setting their email to match any other user's email address—including high-privileged accounts. Upon next login, the attacker gains full access to the targeted account. The linkage persists permanently even if the LDAP email is reverted, creating a lasting account takeover. The attack requires LDAP to be configured and active (non-default) and the attacker must have LDAP authentication credentials and directory write permissions to their own email field. Patches are available in n8n versions 2.4.0 and 1.121.0.
Affected products
- n8n n8n >= 2.0.0-rc.0, < 2.4.0; < 1.121.0
Timeline
- 2026-03-25: disclosed
- 2026-03-25: patched: Fixed in n8n versions 2.4.0 and 1.121.0