n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
n8n Enterprise instances trusting multiple identity providers matched users by subject claim alone, ignoring the issuer—allowing cross-tenant account takeover via any valid token from a different provider.
Summary written by editorial AI · Source link below
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss.
A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in as them. Their password never
Editorial Analysis
Workflow automation platforms like n8n often hold credentials and API keys for dozens of integrations; an authentication bypass turns them into a skeleton key for the entire toolchain.
Patch affected n8n Enterprise instances and verify that all federated authentication services validate both issuer and subject claims.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Vulnerabilities Desk
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More20 Jul
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.20 Jul
- [NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere Schwachstellen20 Jul
- [NEU] [hoch] Grafana: Schwachstelle ermöglicht Manipulation von Dateien20 Jul
- [NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen20 Jul