Critical Flaw in n8n Token Exchange: What You Need to Know (2026)

The recent security vulnerability in n8n, a workflow automation platform, has raised concerns among users and developers alike. This critical flaw, tracked as CVE-2026-59208, could potentially allow attackers to log in as users from another issuer, compromising account security. The issue stems from a misunderstanding of the RFC 7519 standard, where the 'sub' claim is not guaranteed to be unique within the issuer's context, leading to potential identity binding vulnerabilities. This oversight could have far-reaching consequences, especially for Enterprise instances configured to trust multiple external token issuers. The vulnerability is particularly concerning because it affects every n8n release below 2.27.4 and version 2.28.0, and the fix was only recently released on June 24, 2026. The advisory, however, does not specify how an attacker would obtain the token, leaving a gap in the understanding of the full scope of the threat. The CVSS 4.0 vector assigned by GitHub marks the attack requirements as present, but the practical implications of this vulnerability remain unclear. The Hacker News has reached out to n8n for confirmation on the scope and impact of CVE-2026-59208 and will update this story with any response. In the meantime, users are advised to patch their n8n instances to the latest stable build, which is 2.30.6, or cut back to a single trusted issuer or turn off the token exchange feature. While these short-term measures are recommended, they do not fully remediate the risk, and the advisory emphasizes the need for further action to ensure the security of n8n deployments.

Critical Flaw in n8n Token Exchange: What You Need to Know (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Geoffrey Lueilwitz

Last Updated:

Views: 6229

Rating: 5 / 5 (80 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Geoffrey Lueilwitz

Birthday: 1997-03-23

Address: 74183 Thomas Course, Port Micheal, OK 55446-1529

Phone: +13408645881558

Job: Global Representative

Hobby: Sailing, Vehicle restoration, Rowing, Ghost hunting, Scrapbooking, Rugby, Board sports

Introduction: My name is Geoffrey Lueilwitz, I am a zealous, encouraging, sparkling, enchanting, graceful, faithful, nice person who loves writing and wants to share my knowledge and understanding with you.