CuraSec

Plan archived

n8n JWT Cross-Issuer Flaw Enables Account Takeover on Enterprise

2026-07-17 12:06 UTC · The Hacker News · read the source ↗ #authentication-bypass#jwt#workflow-automation
  • Engineer — Plan: Any n8n Enterprise deployment trusting multiple external JWT issuers is exposed to cross-tenant account takeover via iss claim bypass; patch n8n to the fixed version and audit multi-issuer OIDC/JWT configurations now.
  • SOC/IR — Skip
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.