CVE-2026-59259 Details
Description
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions but without the externalSecret:list scope can embed external secret references into credentials in forms the static validation does not detect; these references resolve at workflow execution time, exposing secret values the user is not authorized to access. This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use.
A permission bypass vulnerability has been identified in n8n versions prior to 1.123.61, 2.27.4, and 2.28.1. This vulnerability arises from a mismatch between the static validation check and the runtime expression engine in external secrets handling. An authenticated user with permission to create or update credentials, but lacking the 'externalSecret:list' scope, can embed external secret references into credentials in a way that bypasses static validation. These references are resolved during workflow execution, potentially exposing unauthorized secret values. This issue only affects instances with an external secrets provider configured and Advanced Permissions enabled.
Users are advised to upgrade to n8n versions 1.123.61, 2.27.4, or 2.28.1. If an immediate upgrade is not possible, consider restricting credential creation and update permissions to trusted users and auditing existing credentials for unauthorized external secret references.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-jp7m-xcgx-57qm | [email protected] | Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-permission-bypass-via-expression-parser-mismatch-in-external-secrets | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 1.123.61 >= 2.0.0, < 2.27.4 2.28.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |