What is CVE-2026-72763?
CVE-2026-72763 is a vulnerability in n8n where credential access is only validated for top-level credentials of a node, but not for those referenced inside an inline workflow JSON within an Execute Sub-workflow node. When workflow sharing is enabled, a user with Editor access could potentially exploit this to gain unauthorized access to credentials. Upgrading to versions 1.123.67, 2.31.5, or 2.32.1 is required to remediate the issue.
Azərbaycanca: CVE-2026-72763 n8n platformunda aşkar edilmiş boşluqdur ki, burada `Execute Sub-workflow` node daxilindəki inline workflow JSON-da istinad edilən credential-lar üçün giriş yoxlaması düzgün aparılmır. Bu, workflow paylaşımı aktiv olduqda Editor rolu olan istifadəçiyə potensial olaraq icazəsiz credential-lara çıxış imkanı verə bilər. Təsirə məruz qalmamaq üçün sisteminizi 1.123.67, 2.31.5 və ya 2.32.1 versiyalarına yeniləməlisiniz.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: n8n
FAQ1
Under what condition can CVE-2026-72763 be exploited in n8n?
This vulnerability can be exploited only when workflow sharing is enabled. In such an environment, a user with Editor access could gain unauthorized access to credentials referenced inside an inline workflow JSON within an Execute Sub-workflow node.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.