CVE-2026-59208 | n8n Enterprise Authentication Flaw Could Allow Cross-Issuer Account Takeover
A token exchange vulnerability in n8n Enterprise lets valid JWTs from one trusted identity provider authenticate as users from another issuer when subject identifiers collide. Imagine typing no password at all. None. Zero keystrokes. Yet suddenly, you’re inside someone else’s account. Their workflows. Their data. Their entire digital workspace, laid bare before you. That is … Read more
Automation is powerful. But the moment your workflows start moving real data—customer details, API keys, internal notifications—another question appears.