CVE Tools

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

The Hacker NewsBy The Hacker News

Patchn8n Enterprise

Our summary

n8n, the workflow automation platform, addressed a critical vulnerability in its Enterprise edition that allowed attackers to impersonate users from different token issuers. The flaw, tracked as CVE-2026-59208, stemmed from improper validation of the iss (issuer) field in JSON Web Tokens (JWTs), allowing a valid token from one issuer to log in as a user from another. This issue only affects n8n Enterprise instances configured to trust multiple external issuers. The fix was deployed on June 24, with updated versions 2.27.4 and 2.28.1. Affected organizations are advised to upgrade immediately or disable the token exchange feature if patching is delayed.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store