logo

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

ID: 3b42e448-144b-59ed-8055-aa1ef302a91d

STIX ID: report--3b42e448-144b-59ed-8055-aa1ef302a91d

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: [email protected] (The Hacker News)

...
...

The article details CVE-2026-59208: an identity-binding bug in n8n's Enterprise token-exchange feature that matched JWTs by subject ('sub') but ignored issuer ('iss'), allowing a valid token from one trusted issuer with a colliding subject to authenticate as a different local user; the flaw affects releases before 2.27.4 and 2.28.0, was fixed in 2.27.4/2.28.1, has limited exposure (Enterprise token-exchange must be enabled and trust multiple issuers), and has no public proof-of-concept or reported exploitation as of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.