Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59208

Опубликовано: 09 июл. 2026
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия до 2.27.4 (исключая)
cpe:2.3:a:n8n:n8n:2.28.0:*:*:*:*:node.js:*:*

EPSS

Процентиль: 24%
0.00314
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-287
CWE-346

Связанные уязвимости

github
около 1 месяца назад

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

EPSS

Процентиль: 24%
0.00314
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-287
CWE-346