Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4309 articles · 196687 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-59259EXPLOITEDPATCHED
n8n · n8n

n8n - Permission Bypass via Expression Parser Mismatch in External Secrets

Description

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions but without the externalSecret:list scope can embed external secret references into credentials in forms the static validation does not detect; these references resolve at workflow execution time, exposing secret values the user is not authorized to access. This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use.

Affected Products

VendorProductVersions
n8nn8nnpm/n8n: < 1.123.61, npm/n8n: >= 2.28.0, < 2.28.1, npm/n8n: >= 2.0.0-rc.0, < 2.27.4

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
npmn8nGHSA85%

References

  • https://github.com/n8n-io/n8n/security/advisories/GHSA-jp7m-xcgx-57qm(vendor-advisory)
  • https://www.vulncheck.com/advisories/n8n-permission-bypass-via-expression-parser-mismatch-in-external-secrets(third-party-advisory)

Related News (2 articles)

Tier B
CCCS Canada33d ago
n8n security advisory (AV26-733)
→ No new info (linked only)
Tier C
VulDB40d ago
CVE-2026-59259 | n8n prior 1.123.61/2.27.4/2.28.1 External Secrets permission
→ No new info (linked only)
CVSS 3.17.5 MEDIUM
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
n8n@1.123.61n8n@2.28.1n8n@2.27.4
CWECWE-639
PublishedJul 15, 2026
Last enriched40d agov2
Tags
code executionauthenticatedgit node
Trending Score0
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-59253
n8n - Improper Authorization in Workflow Assignment to Folders
MEDIUMCVE-2026-58661
n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
MEDIUMCVE-2026-59254EXP
n8n - External Secrets Disclosure via Workflow Node Expressions
NONECVE-2026-56354EXP
n8n - Cross-Site Scripting and Open Redirect in Form Node
NONECVE-2026-56360
n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: description, severity, cvssEstimate, activelyExploited
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 40d ago
v2Tier C40d ago

Updated description with new details, changed severity to HIGH, and set CVSS estimate to 7.5.

descriptionseveritycvssEstimateactivelyExploited
via VulDB
v140d ago

Initial creation