Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

n8n and n8n-MCP flaws expose credentials and cross-tenant workflow backups

Three disclosed vulnerabilities in the n8n workflow automation ecosystem allowed AI Agents to bypass a credential's Allowed HTTP Request Domains restriction via an MCP tool pointed at an attacker-controlled URL (CVE-2026-59207), and let authenticated tenants in n8n-MCP multi-tenant HTTP mode read or delete other tenants' workflow version backups containing credential references and authorization headers (CVE-2026-54052, CVE-2026-55608). All issues were fixed in updated releases.

Disclosed 9 July 2026 · Record updated 13 September 2026

Impact

A member-level user with use-only access to a shared credential could exfiltrate that secret to an external server; authenticated tenants in n8n-MCP multi-tenant deployments could read, delete or destroy other tenants' workflow version snapshots including full node definitions, credential references and authorization headers.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-59207
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54052
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55608