SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-59259

MEDIUM · CVSS 6.5 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability affects n8n versions prior to 1.123.61, 2.27.4, and 2.28.1, allowing authenticated users with permission to create or update credentials to bypass access controls on external secrets. This can lead to unauthorized exposure of sensitive secret values during workflow execution, particularly in environments utilizing external secrets providers and Advanced Permissions. Organizations using these configurations should prioritize patching to mitigate the risk of credential leaks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59259
Severity
MEDIUM
CVSS
6.5
EPSS
0.32%

Original NVD Description

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions but without the externalSecret:list scope can embed external secret references into credentials in forms the static validation does not detect; these references resolve at workflow execution time, exposing secret values the user is not authorized to access. This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use.

Related CVEs

Other vulnerabilities affecting the same vendor(s)