Vulnerability intelligence
CVE-2026-59208
n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1.
CVSS Score
7.6
High
EPSS — Exploit Probability
0.3%
Riskier than 24% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jul 17, 2026 · latest Jul 17, 2026
Coverage timeline
-
CVE-2026-59208 Flaw Lets Attackers Impersonate n8n Userssocradar.io · Jul 17, 2026