Junglewise Threat Intelligence

n8n permission bypass via expression parser mismatch in external secrets

Severity: low · CVSS 3.1 · Published 2026-07-15

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and execute automated tasks. A permission bypass vulnerability exists where authenticated users with credential creation/update permissions but lacking external secrets access can still view restricted secret values by embedding specially-crafted references into credentials. This could lead to unauthorized disclosure of sensitive API keys and passwords in environments using advanced permissions.

Technical details

The vulnerability stems from a mismatch between static validation performed during credential creation/update and the runtime expression engine evaluation. An authenticated attacker with credential management permissions but without the externalSecret:list scope can embed external secret references in credential fields that pass static validation but resolve at runtime to expose unauthorized secret values. The attack requires: (1) authentication to n8n, (2) credential create/update permissions, (3) an external secrets provider configured, and (4) Advanced Permissions enabled. This is an authorization bypass (CWE-639) that escalates existing legitimate permissions to access restricted data. Patches are available in versions 1.123.61, 2.27.4, and 2.28.1 or later.

Affected products

  • n8n n8n before 1.123.61, 2.27.4, and 2.28.1

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: patched: Patches released in versions 1.123.61, 2.27.4, and 2.28.1

References

Related threats