CVE-2026-103246
HIGH
NVD
CVSS Score
7.7
Severity
HIGH
Published
Oct 01, 2026
Vendor
unknown
Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.