CVE-2026-103256
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Oct 01, 2026
Vendor
unknown
Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.