CVE-2026-77073

n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:2.34.0:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-20 12:16

Updated : 2026-09-01 19:14


NVD link : CVE-2026-77073

Mitre link : CVE-2026-77073

CVE.ORG link : CVE-2026-77073


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-639

Authorization Bypass Through User-Controlled Key