How to use this reference
Apply object authorization consistently to discovery, authorization and revocation, including indirect workflow references. Maintainers list fixes in 1.123.55, 2.25.7 and 2.26.2. Restricting access to trusted users or disabling the feature is temporary mitigation, explicitly not full remediation.
Before reading
- Basic federation and object-level authorization concepts
Context and limits
- Requires an Enterprise instance with Dynamic Credentials enabled and an authenticated session, without requiring project membership or credential sharing.
- Jubke is the publishing account; Solidscripting and Har1sh-k are credited reporters. Article authorship is not established.
- Impact statements lack separate observed-versus-modeled demonstrations. Exfiltration and persistence remain maintainer-described consequences.
- Fixed versions apply within respective release lines; software release dates are not established.
- Distinct from the existing refresh-grant audience-binding resource.
Sources and provenance
- Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints n8n · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.