CVE-2026-59208
MEDIUMn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
Title source: cnaDescription
n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/n8n-io/n8n/security/advisories/GHSA-mq3m-f8x3-579w
X_Refsource_Misc x_refsource_misc
https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4
X_Refsource_Misc x_refsource_misc
https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1
Scores
CVSS v3
6.8
EPSS
0.0026
EPSS Percentile
17.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
CWE-346
Status
published
Products (6)
n8n/n8n
2.28.0
n8n/n8n
< 2.27.4
n8n-io/n8n
< 2.27.4
n8n-io/n8n
>= 2.28.0, < 2.28.1
npm/n8n
0 - 2.27.4npm
npm/n8n
2.28.0 - 2.28.1npm
Published
Jul 09, 2026
Tracked Since
Jul 09, 2026