BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

n8n bug lets one token claim login into wrong user account

Critical n8n identity-binding flaw CVE-2026-59208 allowed account takeover via cross-issuer impersonation ignoring JWT issuer claim

  • A critical identity-binding flaw in n8n‘s token exchange allowed account takeover when multiple external issuers were trusted.
  • The vulnerability (CVE-2026-59208) matched JWTs on the sub claim alone, ignoring iss, enabling cross-issuer impersonation.
  • n8n patched the issue on June 24 in versions 2.27.4 and 2.28.1; the CVE went public on July 9 with a CVSS 4.0 score of 7.6 (high).

n8n, the workflow automation platform, patched a critical identity-binding bug in its Enterprise token exchange feature that could let an attacker take over any user account. The flaw, tracked as CVE-2026-59208, affected instances configured to trust more than one external JWT issuer.

- Advertisement -

The platform matched incoming tokens to local accounts using only the sub claim, completely ignoring the iss field. According to n8n’s advisory, a valid token from issuer A with a sub belonging to a user under issuer B logged you in as that user — no password needed. The bug was discovered by bearsyankees, a profile associated with AI security firm Strix, which detailed the flaw at the token-exchange flow.

Token exchange implements RFC 8693, allowing OEM partners to embed n8n without a second login. Trusted keys are set in N8N_TOKEN_EXCHANGE_TRUSTED_KEYS, but the matching logic violated RFC 7519, which requires that a user identifier be the pair of iss and sub, not just sub alone.

The flaw only affects Enterprise instances with token exchange enabled and at least two external issuers configured. n8n says nothing else is impacted. The advisory does not specify how an attacker obtains a valid token, but the CVSS 4.0 vector notes attack requirements are present.

GitHub assigned a CVSS 4.0 score of 7.6 (high), while NVD rated it 6.8 on CVSS 3.1 (medium). CISA’s July 13 assessment found no evidence of exploitation, and no public proof-of-concept has emerged. Just two weeks prior, n8n patched CVE-2026-54305, another Enterprise-only flaw that allowed authenticated users to overwrite others’ OAuth tokens.

- Advertisement -

Patched versions are 2.27.4 and 2.28.1; all earlier releases and 2.28.0 are vulnerable. The fix is not mentioned in changelogs, so administrators relying on release notes may miss it. Until upgrading, n8n recommends reducing trusted issuers to one or disabling token exchange entirely.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tokenized RWA Deposits Triple to $7.4B, DeFi Falls 15%

Deposits of tokenized real-world assets into DeFi lending venues and exchanges more than tripled...

Crypto perp futures volume hits 31-month low at $4T

Crypto perpetual futures trading volume on centralized exchanges dropped to $4 trillion in July,...

AI discovers new HTTP desync attacks, 700+ sites at risk

PortSwigger's AI system, HTTP Terminator, autonomously generated and validated novel HTTP desynchronization attacks after...

US Senate Delays Crypto Clarity Act Vote Until September

The U.S. Senate will not vote on the Clarity Act before its August recess,...

Trump could net big tax windfall from crypto ethics plan

A bipartisan ethics proposal tied to a crypto market structure bill includes a tax-deferral...

Must Read

6 Best VPN Providers That Accept Monero

Privacy and anonymity are probably the most important things that we should all consider in today's internet era. Although there are a lot of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading