n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
ID: 3b42e448-144b-59ed-8055-aa1ef302a91d
STIX ID: report--3b42e448-144b-59ed-8055-aa1ef302a91d
Feed Name: The Hacker News
The article details CVE-2026-59208: an identity-binding bug in n8n's Enterprise token-exchange feature that matched JWTs by subject ('sub') but ignored issuer ('iss'), allowing a valid token from one trusted issuer with a colliding subject to authenticate as a different local user; the flaw affects releases before 2.27.4 and 2.28.0, was fixed in 2.27.4/2.28.1, has limited exposure (Enterprise token-exchange must be enabled and trust multiple issuers), and has no public proof-of-concept or reported exploitation as of the advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
