n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another project and send its decrypted secret to an attacker-controlled endpoint. The affected authorization boundary is packages/cli/src/modules/log-streaming.ee/destinations/destination-credentials-access.ts and the credential:read scope. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.76 | Release Notes |
| https://github.com/n8n-io/n8n/releases/tag/n8n@2.37.7 | Release Notes |
| https://github.com/n8n-io/n8n/releases/tag/n8n@2.38.2 | Release Notes |
| https://github.com/n8n-io/n8n/security/advisories/GHSA-pq6c-vh67-xpm3 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-09-08 22:19
Updated : 2026-09-10 21:02
NVD link : CVE-2026-86993
Mitre link : CVE-2026-86993
CVE.ORG link : CVE-2026-86993
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-862
Missing Authorization
