vulns.co
/
GKData.io MCP

n8n · 1 min read

n8n Dynamic Credentials: authorize credential lifecycle operations

CVE-2026-54305 concerns authenticated Dynamic Credentials operations missing workflow and credential ownership or scope checks. Maintainers report unauthorized credential metadata access, OAuth identity replacement and token revocation. Subsequent integration execution may use the substituted identity; production exploitation is not established.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Apply object authorization consistently to discovery, authorization and revocation, including indirect workflow references. Maintainers list fixes in 1.123.55, 2.25.7 and 2.26.2. Restricting access to trusted users or disabling the feature is temporary mitigation, explicitly not full remediation.

Before reading

  • Basic federation and object-level authorization concepts

Context and limits

  • Requires an Enterprise instance with Dynamic Credentials enabled and an authenticated session, without requiring project membership or credential sharing.
  • Jubke is the publishing account; Solidscripting and Har1sh-k are credited reporters. Article authorship is not established.
  • Impact statements lack separate observed-versus-modeled demonstrations. Exfiltration and persistence remain maintainer-described consequences.
  • Fixed versions apply within respective release lines; software release dates are not established.
  • Distinct from the existing refresh-grant audience-binding resource.

Sources and provenance

  1. Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints n8n · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software