CVE-2026-45732Disclosure(n8n / n8n)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-only access to a shared credential could initiate an OAuth reconnect flow and overwrite the stored token material for that credential with tokens bound to an external account they control. Workflows relying on the affected credential would subsequently execute under the attacker's OAuth identity, enabling data exfiltration to attacker-controlled external services and persistent takeover of shared integrations. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-14: 2Technical Details · 2026-05-14: 205-14
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - n8n Multiple Critical Vulnerabilities (CVE-2026-44791, CVE-2026-44792, CVE-2026-45732, CVE-2026-44789, CVE-2026-44790) Multiple high-severity vulnerabilities were disclosed in n8n, including Prototype Pollution leading to RCE (via XML Node and HTTP Request Node), Arbitrary File Read via Git Node (CLI argument injection), Source Control Pull SQL Injection (PostgreSQL), Cross-user OAuth Credential Takeover, and Credential Exfiltration via SSRF Bypass. These issues can allow remote code execution, unauthorized data access, and credential theft depending on the configuration. 👉Affected: n8n < 1.123.43 | < 2.22.1 | < 2.20.7

    Post summary

    The text announces high‑severity vulnerabilities in n8n, detailing the types of exploits and affected versions, but does not mention PoCs, active attacks, patches, or false‑positive claims.

    00020109
    255 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 n8n, OAuth Credential Reconnect Authorization Bypass, #CVE-2026-45732 (High) https://dailycve.com/n8n-oauth-credential-reconnect-authorization-bypass-cve-2026-45732-high/

    Post summary

    A publicly disclosed high‑severity CVE‑2026‑45732 affecting n8n’s OAuth credential reconnect authorization has been announced.

    0000051
    202 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more