
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59259 is a permission bypass vulnerability in n8n, the open-source workflow automation platform, affecting its external secrets handling mechanism. The flaw stems from a mismatch between the static validation check and the runtime expression engine, allowing authenticated users to access secrets they are not authorized to view. It affects n8n versions before 1.123.61, before 2.27.4, and version 2.28.0 (fixed in 2.28.1), and only impacts deployments where an external secrets provider is configured and Advanced Permissions are enabled. The vulnerability was published on July 15, 2026, with a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.0 (Medium) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), arising because the static validation layer used during credential creation or update does not recognize certain forms of external secret references that the runtime expression engine does resolve. An authenticated user who holds credential create or update permissions but lacks the externalSecret:list scope can craft credential fields containing external secret references in a syntax that bypasses static validation. When a workflow using those credentials is executed, the runtime expression engine resolves the embedded references, exposing the secret values to the unauthorized user. The attack requires network access to the n8n instance, low privileges (a valid account with credential permissions), and the specific deployment conditions of an active external secrets provider and Advanced Permissions (GitHub Advisory, Github Advisory).
Successful exploitation results in unauthorized disclosure of secret values stored in an external secrets provider (e.g., API keys, passwords, tokens), constituting a high confidentiality impact with no integrity or availability impact. The exposed secrets could enable lateral movement or privilege escalation if the compromised secrets grant access to other systems or services integrated with the n8n workflows. The scope is limited to deployments with both an external secrets provider configured and Advanced Permissions enabled, reducing the overall attack surface (GitHub Advisory, Github Advisory).
create or update permissions but lacks the externalSecret:list scope.externalSecret:list scope, particularly if followed by workflow execution events involving those credentials.Upgrade n8n to version 1.123.61, 2.27.4, or 2.28.1 (or later) to fully remediate the vulnerability. If immediate upgrading is not possible, restrict credential creation and update permissions to fully trusted users only, and audit existing credentials for unexpected external secret references. These workarounds do not fully eliminate the risk and should be treated as short-term measures only (GitHub Advisory).
The vulnerability was reported by security researcher YLChen-007 and published by n8n maintainer Jubke via GitHub Security Advisories on June 24, 2026, with CVE assignment and NVD publication following on July 15, 2026. No significant broader media coverage or notable social media commentary has been identified beyond the official advisory and standard vulnerability database entries (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."