CVE-2026-103256: n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.39.6 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.40.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are n8n releases before 2.39.6, plus version 2.40.0. The issue applies to the Wekan and Baserow username-and-password credential types.
What access does an attacker need to exploit this?
An attacker needs permission to update credentials. They can change the credential host field to an arbitrary host and cause account passwords to be sent there.
Does domain validation prevent exploitation?
No. The vulnerability bypasses domain validation controls because the preAuthentication hook sends the password to an unvalidated host.
What versions address the issue?
Upgrade to n8n 2.39.6 or later, or to 2.40.1 or later within the 2.40.x release line.