CVE-2026-59254 Details
Description
n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by referencing them in node expressions without requiring explicit secrets access permissions.
A vulnerability allowing information disclosure exists in n8n versions prior to 2.28.1. This issue arises because external secrets are improperly resolved in workflow node expressions, outside the intended credentials scope. Authenticated project editors can access plaintext values of external secrets by referencing them in node expressions, without needing explicit permissions to access those secrets. This vulnerability only affects instances with the external secrets feature enabled.
Users should upgrade to n8n version 2.28.1 or later. If an immediate upgrade is not possible, project membership should be restricted to trusted users, and editor access should be avoided on instances with external secrets configured.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n | < 2.28.1 (semver) < 2.27.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |
Volerion