CVE-2026-33722
Last modified
CVE-2026-33722 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plaintext value when saving the credential. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plaintext value when saving the credential. This bypassed the `externalSecret:list` permission check and allowed access to secrets stored in connected vaults without admin or owner privileges. This issue requires the instance to have an external secrets vault configured. The attacker must know or be able to guess the name of a target secret. The issue has been fixed in n8n versions 1.123.23 and 2.6.4. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Restrict n8n access to fully trusted users only, and/or disable external secrets integration until the patch can be applied. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| N8n | N8n | < 1.123.23 |
| N8n | N8n | >= 2.0.0, < 2.6.4 |
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-fxcw-h3qj-8m8pMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33722?
How severe is CVE-2026-33722?
How do I fix CVE-2026-33722?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33716WWBN AVideo is an open source video platform. In versions up…9.4
- CVE-2026-33717WWBN AVideo is an open source video platform. In versions up…8.8
- CVE-2026-33718OpenHands is software for AI-driven development. Starting in…9.9
- CVE-2026-33719WWBN AVideo is an open source video platform. In versions up…8.6
- CVE-2026-33720n8n is an open source workflow automation platform. Prior to…4.2
- CVE-2026-33721MapServer is a system for developing web-based GIS applicati…7.5
- CVE-2026-33723WWBN AVideo is an open source video platform. In versions up…6.5
- CVE-2026-33724n8n is an open source workflow automation platform. Prior to…7.4
- CVE-2026-33725Metabase is an open source business intelligence and embedde…7.2
- CVE-2026-33726Cilium is a networking, observability, and security solution…4.3
- CVE-2026-33727Pi-hole is a Linux network-level advertisement and Internet …6.7
- CVE-2026-33728dd-trace-java is a Datadog APM client for Java. In versions …9.8
Are you affected by CVE-2026-33722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
