CVE-2026-103259: n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.39.6 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.40.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are n8n releases before 2.39.6, plus version 2.40.0. Version 2.40.1 is not listed as affected.
What access and interaction does an attacker need?
The attacker needs resolver registration capability and must configure a fallback resolver that points to an attacker-controlled endpoint. A collaborator must then go through the account connection flow, with user interaction required for exploitation.
What is the impact if exploitation succeeds?
An attacker can capture a collaborator's session token during Dynamic Credentials authorization or revocation. The captured token can enable unauthorized access to credentials.
Which functionality is involved?
The issue affects the Dynamic Credentials authorize and revoke endpoints, specifically when a fallback resolver is used during account connection.