LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-56348

n8n · n8n

Published
CVSS9.1
Severitycritical
WeaknessCWE-918
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Description

n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive authentication data.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-56348

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-56348.