CVE-2026-72772
8.9n8n-io · n8n
A weak password recovery mechanism in n8n-io n8n allows authenticated attackers to potentially bypass authentication protocols via token exchange.
Executive summary
A critical authentication bypass vulnerability in n8n-io n8n allows authenticated attackers to manipulate token exchange mechanisms, risking full system access.
Vulnerability
This vulnerability involves a weak password recovery mechanism (CWE-640) that can be exploited by an authenticated user to perform an authentication bypass. The vulnerability leverages flaws in the token exchange process to elevate privileges or hijack sessions.
Business impact
With a CVSS score of 8.9, this vulnerability presents a significant risk to workflow automation security. Successful exploitation could allow an attacker to hijack active sessions or bypass authentication, granting them full control over workflows, connected credentials, and integrated third-party services.
Remediation
Immediate Action: Update the n8n installation to version 2.32.1 or 2.31.5 immediately to resolve the token exchange flaw.
Proactive Monitoring: Review application and access logs for suspicious token exchange patterns or unauthorized account access events.
Compensating Controls: Restrict access to the n8n administrative interface to known IP addresses and enforce multi-factor authentication (MFA) where possible to mitigate the impact of compromised credentials.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
This flaw requires urgent attention due to the high severity and the potential for complete system compromise. Administrators must apply the vendor-provided patches (2.32.1 or 2.31.5) as soon as possible to secure the n8n platform against potential exploitation.