| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pq6c-vh67-xpm3 | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 10 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
N8n
N8n n8n |
|
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| Metrics |
cvssV3_1
|
Wed, 09 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another project and send its decrypted secret to an attacker-controlled endpoint. The affected authorization boundary is packages/cli/src/modules/log-streaming.ee/destinations/destination-credentials-access.ts and the credential:read scope. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2. | |
| Title | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-09T16:04:06.689Z
Reserved: 2026-09-08T16:44:23.781Z
Link: CVE-2026-86993
Updated: 2026-09-09T15:49:57.523Z
Status : Analyzed
Published: 2026-09-08T22:19:17.810
Modified: 2026-09-10T21:02:49.697
Link: CVE-2026-86993
No data.
OpenCVE Enrichment
Updated: 2026-09-09T09:00:11Z
Github GHSA