CVE-2026-33722: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33722 is an external secrets authorization bypass vulnerability in n8n, an open-source workflow automation platform. An authenticated user without the externalSecret:list permission can reference a secret by its external name within a credential and retrieve its plaintext value upon saving, effectively bypassing the intended permission check. The vulnerability affects n8n versions prior to 1.123.23 (v1 branch) and versions 2.0.0-rc.0 through 2.6.4 (v2 branch). It was published on March 25, 2026, with patches released the same day. The CVSS v4.0 base score is 7.3 (High); the CVSS v3.1 base score is 5.3 (Medium) (GitHub Advisory, n8n Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): the credential-saving workflow resolves and returns the plaintext value of an externally referenced secret without verifying that the requesting user holds the externalSecret:list permission. An attacker with any authenticated access to the n8n instance can craft a credential that references a known or guessed secret name from the connected vault (e.g., HashiCorp Vault, AWS Secrets Manager), then trigger a save operation to receive the resolved plaintext secret in the response. Two preconditions must be met: the n8n instance must have an external secrets vault configured, and the attacker must know or be able to enumerate/guess the target secret's name (GitHub Advisory, n8n Advisory).

Impact

Successful exploitation allows a low-privileged authenticated user to read plaintext values of secrets stored in connected external vaults without admin or owner privileges, resulting in a high confidentiality impact. Exposed secrets may include API keys, database passwords, service account credentials, or other sensitive values managed by the vault, enabling lateral movement to downstream systems that rely on those credentials. Integrity and availability of the n8n instance itself are not directly affected, but the subsequent system impact (confidentiality, integrity, and availability of systems whose credentials are exposed) is rated High under CVSS v4.0 (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.013–0.017%, placing it in the 4th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The attack requires authentication and knowledge of secret names, which moderately limits opportunistic exploitation, though insider threats or users with partial knowledge of vault naming conventions represent a realistic risk.

Exploitation steps

  1. Reconnaissance: Identify an n8n instance (version < 1.123.23 or 2.0.0-rc.0 to < 2.6.4) with an external secrets vault configured. Confirm the instance is accessible and that the attacker has a valid low-privileged user account.
  2. Enumerate or guess secret names: Attempt to identify secret names used in the vault through social engineering, reviewing shared workflows, or systematic guessing of common naming conventions (e.g., DB_PASSWORD, API_KEY, AWS_SECRET_ACCESS_KEY).
  3. Craft a malicious credential: Using the n8n UI or API, create or edit a credential and reference the target secret by its external name in a credential field that supports external secret resolution (e.g., using the ={{ $secrets.SECRET_NAME }} syntax or equivalent external secret reference format).
  4. Trigger credential save: Save the credential. During the save operation, n8n resolves the external secret reference without checking the externalSecret:list permission, returning the plaintext secret value.
  5. Retrieve the plaintext secret: Observe the resolved plaintext value in the API response or within the saved credential's field, successfully bypassing the authorization control (GitHub Advisory, n8n Advisory).

Indicators of compromise

  • Logs: n8n application logs showing credential create/update API calls (POST /api/v1/credentials or PATCH /api/v1/credentials/:id) from users who do not hold the externalSecret:list permission, particularly if the credential payload contains external secret references.
  • Logs: Repeated credential save operations by the same low-privileged user in a short time window, potentially indicating secret name enumeration attempts.
  • Network: API requests to the n8n credential endpoints containing external secret reference syntax (e.g., patterns matching $secrets.<name>) originating from non-admin accounts.
  • Vault Audit Logs: Unexpected secret read events in the connected vault (e.g., HashiCorp Vault audit log, AWS CloudTrail) triggered by the n8n service account at times correlating with credential save operations by low-privileged users.

Mitigation and workarounds

Upgrade n8n to version 1.123.23 (v1 branch) or 2.6.4 (v2 branch) or later, as these releases contain the fix that enforces the externalSecret:list permission check during credential saving. If immediate upgrading is not possible, administrators should apply the following temporary mitigations: (1) restrict n8n access to fully trusted users only, and (2) disable the external secrets integration until the patch can be applied. Note that these workarounds do not fully eliminate the risk and are intended only as short-term measures (GitHub Advisory, n8n Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management