CVE-2026-103256

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨CRITICAL & HIGH - Multiple Critical Vulnerabilities in n8n (CVE-2026-103246 – CVE-2026-103259) Multiple security vulnerabilities were identified in n8n workflow automation platform affecting versions prior to 1.78.0. Flaws range from unauthenticated arbitrary file read (CVE-2026-103253), RCE in Form Trigger (CVE-2026-103246), SSH command injection (CVE-2026-103257), dynamic expression code execution (CVE-2026-103250), OAuth2 auth bypass (CVE-2026-103256), and workspace privilege escalation (CVE-2026-103247), alongside SSRF, Stored XSS, IDOR, and credential leakage issues. 👉Affected: n8n < 1.78.0 | Upgrade to 1.78.0 or later

    1000065
    308 followersView on X

Explore more