CVE-2026-72772
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
Summary
Remediation
Upgrade to the fixed version using your package manager.
npm install n8n@2.31.5
npm install n8n@2.32.1
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (2)
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 9.5 score means for each attack dimension.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-8342-988q-86crWEB
- https://github.com/n8n-io/n8n/commit/f69dfc6dd2178a14ea1624d2e1d403c2e755042fWEB
- https://github.com/n8n-io/n8nPACKAGE
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.31.5WEB
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.32.1WEB
Frequently Asked Questions
- What is CVE-2026-72772?
- n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login This vulnerability has been assigned a severity rating of HIGH (CVSS score: 9.5/10).
- How do I check if my project is affected by CVE-2026-72772?
- CVE-2026-72772 affects n8n. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-72772 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation is straightforward and causes maximum impact. Patch immediately.
Also Known As
Related CVEs
- CVE-2026-25053CRITICAL
n8n has OS Command Injection in Git Node
- CVE-2026-27577CRITICAL
n8n: Expression Sandbox Escape Leads to RCE
- CVE-2025-65964CRITICAL
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
- CVE-2026-44791CRITICAL
n8n Has an XML Node Prototype Pollution Patch Bypass
- CVE-2026-27497CRITICAL
n8n has Potential Remote Code Execution via Merge Node
- CVE-2026-65592HIGH
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
- CVE-2026-65593MEDIUM
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
- CVE-2026-54310MEDIUM
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies