CVE-2026-103246: n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspection
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.39.6 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.40.1
Event History
Frequently Asked Questions
Which n8n releases are affected?
Affected releases are n8n versions before 2.39.6, and 2.40.0 before 2.40.1. Upgrade to 2.39.6 or 2.40.1 or later, as applicable.
What level of access does an attacker need?
The attack is network-reachable and requires low privileges. The attacker must be able to perform inline agent node-tool introspection and reference credential IDs.
Can an attacker target credentials they do not own?
Yes. The flaw is the absence of credential ownership validation, allowing arbitrary credential IDs to be referenced and their plaintext secrets decrypted and sent to attacker-controlled hosts.