How to use this reference
Editorial lesson: an identity association is a security grant with its own approval and revocation requirements. Attribute equality alone should not establish account ownership. Review claim provenance, linking consent and existing association cleanup independently. The maintainer identifies software versions 1.121.0 and 2.4.0 as fixes for their respective release lines.
Before reading
- Basic understanding of authentication, account state and authorization
Context and limits
- Requires enabled LDAP authentication, which is non-default, and an authenticated directory user able to alter their own email attribute. This is a maintainer-described impact, not evidence of a production compromise.
- The advisory recommends temporary LDAP restriction or disabling and account-association review, but calls those measures incomplete. It does not establish automatic removal of previously incorrect links or a patch-release date.
- Jubke published the advisory. Credited reporters are weblover12, 34selen, B0RI, bde574786 and jh-hack. Original report date is not established. Learning prerequisites and design lessons are editorial.
Sources and provenance
- LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover n8n · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.