
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33663 is a credential theft vulnerability in n8n, an open-source workflow automation platform, classified as "Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition." An authenticated user with the global:member role can exploit chained authorization flaws to steal plaintext secrets from generic HTTP credentials (httpBasicAuth, httpHeaderAuth, httpQueryAuth) belonging to other users on the same instance. The vulnerability affects n8n Community Edition versions prior to 1.123.27 (v1 branch), prior to 2.13.3, and version 2.14.0 (v2 branch); Enterprise Edition is not affected. It was disclosed on March 25, 2026, with a CVSS v4.0 score of 8.5 (High) and a CVSS v3.1 score of 6.5 (Medium) (GitHub Advisory, Github Advisory).
The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key): n8n's credential pipeline contains two chained flaws. First, a name-based credential resolution path resolves credentials by name without enforcing ownership or project scope, allowing a member-role user to look up another user's credential ID. Second, the credentials permission checker incorrectly skips validation for generic HTTP credential types (httpBasicAuth, httpHeaderAuth, httpQueryAuth) during pre-execution checks, meaning these credential types bypass the authorization gate entirely. By combining these two weaknesses, an attacker can craft a workflow that references another user's credential by its resolved ID, trigger execution, and receive the decrypted plaintext secret. Native integration credential types (e.g., slackApi, openAiApi, postgres) are not affected because they are not skipped by the permission checker (GitHub Advisory, Github Advisory).
Successful exploitation allows an authenticated member-role user to decrypt and obtain plaintext HTTP credentials (basic auth, header auth, query auth) belonging to any other user on the same n8n Community Edition instance. This can lead to unauthorized access to third-party services and APIs protected by those credentials, potential data exfiltration from downstream systems, and lateral movement into dependent infrastructure. Integrity and availability of the n8n instance itself are not directly impacted, but subsequent systems protected by the stolen credentials face high confidentiality, integrity, and availability risk (GitHub Advisory, Feedly).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.019–0.022%, placing it in the 6th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account with at least global:member role on the target n8n Community Edition instance, limiting the attack surface to insider threats or compromised accounts (GitHub Advisory).
global:member account on a vulnerable n8n Community Edition instance (versions < 1.123.27, < 2.13.3, or = 2.14.0).httpBasicAuth, httpHeaderAuth, or httpQueryAuth credential.global:member user executing workflows that reference credentials not owned by or shared with that user; unexpected workflow executions involving httpBasicAuth, httpHeaderAuth, or httpQueryAuth credential types.httpBasicAuth, httpHeaderAuth, httpQueryAuth).
(GitHub Advisory)Upgrade n8n Community Edition to version 1.123.27 (v1 branch), 2.13.3, or 2.14.1 (v2 branch) or later, as these releases contain the fix (GitHub Advisory). If immediate upgrade is not possible, administrators should: (1) restrict instance access to fully trusted users only, and (2) audit and rotate all generic HTTP credentials (httpBasicAuth, httpHeaderAuth, httpQueryAuth) stored on the instance. Note that these workarounds do not fully remediate the risk. Enterprise Edition users are not affected due to additional permission gates on workflow creation and execution.
Heise Online covered the vulnerability as part of a broader report on critical vulnerabilities threatening the n8n automation platform, noting it alongside other significant security issues (Heise). The vulnerability was reported by security researcher tr4ce-ju and published by n8n maintainer Jubke via GitHub's security advisory process (GitHub Advisory). Beyond Machines also covered n8n's patch release addressing this and related vulnerabilities (Beyond Machines).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."