What is CVE-2026-72772?
CVE-2026-72772 is an account takeover vulnerability in n8n before versions 2.32.1 and 2.31.5, stemming from the Token Exchange Embed Login feature. The flaw occurs because the service does not verify the email claim's verification status upon matching a signed token, allowing unauthorized access. Affected users must update to the patched versions immediately.
Azərbaycanca: CVE-2026-72772, n8n proqramının 2.32.1 (və 2.31.5) öncəsi versiyalarında Token Exchange Embed Login funksiyası vasitəsilə hesab ələ keçirmə zəifliyidir. Xidmət, etibarlı imzalanmış token-dəki e-poçt iddiasının doğrulanıb-doğrulanmadığını yoxlamadığı üçün təsirə məruz qalır. n8n istifadəçiləri dərhal ən son versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which n8n feature is affected by CVE-2026-72772?
CVE-2026-72772 is an account takeover vulnerability affecting the Token Exchange Embed Login feature of n8n.
What should users do to protect against CVE-2026-72772?
To protect against CVE-2026-72772, n8n users must update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.