CVE-2026-103259

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨CRITICAL & HIGH - Multiple Critical Vulnerabilities in n8n (CVE-2026-103246 – CVE-2026-103259) Multiple security vulnerabilities were identified in n8n workflow automation platform affecting versions prior to 1.78.0. Flaws range from unauthenticated arbitrary file read (CVE-2026-103253), RCE in Form Trigger (CVE-2026-103246), SSH command injection (CVE-2026-103257), dynamic expression code execution (CVE-2026-103250), OAuth2 auth bypass (CVE-2026-103256), and workspace privilege escalation (CVE-2026-103247), alongside SSRF, Stored XSS, IDOR, and credential leakage issues. 👉Affected: n8n < 1.78.0 | Upgrade to 1.78.0 or later

    1000065
    308 followersView on X

Explore more