vulns.co
/
GKData.io MCP

n8n · 1 min read

n8n: directory-attribute authority in durable account linking

CVE-2026-33665 describes local-account linkage that trusted a matching LDAP email attribute. The maintainer reports persistent access to the linked account, including administrator authority, even after the directory attribute changed back.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: an identity association is a security grant with its own approval and revocation requirements. Attribute equality alone should not establish account ownership. Review claim provenance, linking consent and existing association cleanup independently. The maintainer identifies software versions 1.121.0 and 2.4.0 as fixes for their respective release lines.

Before reading

  • Basic understanding of authentication, account state and authorization

Context and limits

  • Requires enabled LDAP authentication, which is non-default, and an authenticated directory user able to alter their own email attribute. This is a maintainer-described impact, not evidence of a production compromise.
  • The advisory recommends temporary LDAP restriction or disabling and account-association review, but calls those measures incomplete. It does not establish automatic removal of previously incorrect links or a patch-release date.
  • Jubke published the advisory. Credited reporters are weblover12, 34selen, B0RI, bde574786 and jh-hack. Original report date is not established. Learning prerequisites and design lessons are editorial.

Sources and provenance

  1. LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover n8n · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software