Executive brief
n8n is a workflow automation platform that allows users to create and execute automated tasks. A permission bypass vulnerability exists where authenticated users with credential creation/update permissions but lacking external secrets access can still view restricted secret values by embedding specially-crafted references into credentials. This could lead to unauthorized disclosure of sensitive API keys and passwords in environments using advanced permissions.
Technical details
The vulnerability stems from a mismatch between static validation performed during credential creation/update and the runtime expression engine evaluation. An authenticated attacker with credential management permissions but without the externalSecret:list scope can embed external secret references in credential fields that pass static validation but resolve at runtime to expose unauthorized secret values. The attack requires: (1) authentication to n8n, (2) credential create/update permissions, (3) an external secrets provider configured, and (4) Advanced Permissions enabled. This is an authorization bypass (CWE-639) that escalates existing legitimate permissions to access restricted data. Patches are available in versions 1.123.61, 2.27.4, and 2.28.1 or later.
Affected products
- n8n n8n before 1.123.61, 2.27.4, and 2.28.1
Timeline
- 2026-06-24: disclosed
- 2026-06-24: patched: Patches released in versions 1.123.61, 2.27.4, and 2.28.1