Threat reportVulnerabilityTL-2026-1436
CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token Exchange
CVE-2026-59208 (TL-2026-1436), also tracked as n8n Cross-Issuer Token Exchange Impersonation, is a high-severity software vulnerability scored CVSS 7.6, first published 2026-07-17. It has no confirmed attribution, affects n8n GmbH n8n Enterprise (self-hosted / OEM, Enterprise token-exchange, references 1 CVE (CVE-2026-59208), maps to 10 MITRE ATT&CK techniques (T1078, T1087, T1190), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 7.6/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1436
- Threat ID
- TL-2026-1436
- Also known as
- n8n Cross-Issuer Token Exchange Impersonation
- Severity
- HIGH
- CVSS
- 7.6 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, softwaredevelopment, managedserviceproviders, businessservices, saas
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
How CVE-2026-59208 works
n8n Enterprise's token-exchange feature resolves external identities using only the JWT `sub` claim while ignoring the `iss` claim, letting a holder of a valid token from one trusted issuer impersonate any account whose subject value matches under a second trusted issuer. Requires Enterprise token exchange enabled with 2+ trusted issuers configured; affects n8n < 2.27.4 and 2.28.0, fixed in 2.27.4 and 2.28.1.
CVE-2026-59208 is an improper-authentication / origin-validation vulnerability (CWE-287, CWE-346) in n8n's Enterprise-only, preview-flagged token-exchange capability, activated via the `N8N_TOKEN_EXCHANGE_TRUSTED_KEYS` configuration. RFC 7519 specifies that a JWT subject (`sub`) identifier is guaranteed unique only within the context of its issuing authority (`iss`); correct identity binding therefore requires the composite `(iss, sub)` pair. n8n's token-exchange identity-resolution logic instead matched external identities to local accounts using the `sub` claim alone.
In a deployment configured to trust two or more external token issuers (a supported pattern for OEM/white-label partner integrations), an attacker who can obtain a valid, properly signed JWT from ANY one of the trusted issuers can present it to n8n. If that token's `sub` value happens to collide with (or is deliberately crafted/obtained to match) the `sub` of a victim account registered under a DIFFERENT trusted issuer, n8n resolves the token to the victim's local account and issues that victim's session — full account takeover with no password, MFA bypass, or credential theft required against the victim directly. The attacker only needs standing as a legitimate user of any one trusted issuer plus knowledge (or a guess) of a colliding subject identifier.
Exploitation is entirely configuration-gated: single-issuer n8n deployments, deployments that do not enable Enterprise token exchange, and deployments with only one trusted issuer are not exposed. This preconditions-heavy nature explains the scoring divergence between GitHub's CNA (CVSS 4.0, 7.6/HIGH, emphasizing high confidentiality/integrity impact once conditions are met) and NVD (CVSS 3.1, 6.8/MEDIUM, emphasizing the high attack-complexity precondition of a multi-issuer configuration). n8n shipped fixes in 2.27.4 and 2.28.1 on 2026-06-24, ahead of the CVE's public disclosure on 2026-07-09 and CISA-ADP vulnrichment assessment on 2026-07-13. As of 2026-07-16 there is no public PoC and no confirmed in-the-wild exploitation; the vulnerability was responsibly disclosed by researcher bearsyankees (affiliated with Strix AI) via GitHub Security Advisory GHSA-mq3m-f8x3-579w.
Impact once exploited: because n8n workflows routinely hold stored credentials for third-party SaaS/cloud/database connections, an attacker who impersonates a victim account inherits that victim's workflow access — enabling data collection from connected services, modification/creation of automations (including ones that exfiltrate data over the workflow's own outbound HTTP nodes), and lateral movement into every system the victim's n8n identity is authorized to reach.
MITRE ATT&CK techniques used in TL-2026-1436
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
Privilege Escalation
Defense Evasion
Discovery
Collection
T1213 Data from Information Repositories
lateral-movement
T1550 Use Alternate Authentication Material
Impact
Exfiltration
T1567 Exfiltration Over Web Service
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
Credential Access
Affected products and versions in CVE-2026-59208
- n8n GmbH — n8n Enterprise (self-hosted / OEM, Enterprise token-exchange feature)
Vulnerable versions: < 2.27.4; 2.28.0
Fixed in: 2.27.4; 2.28.1; 2.28.1+
Remediation for CVE-2026-59208
Patches
- n8n 2.27.4 (https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4)
- n8n 2.28.1 (https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1)
Immediate actions
- Upgrade n8n Enterprise to 2.27.4 or 2.28.1+ (or later) where the (iss, sub) composite identity check is enforced
- Until upgraded, reduce N8N_TOKEN_EXCHANGE_TRUSTED_KEYS to a single trusted issuer to eliminate the collision precondition
- Disable Enterprise token exchange entirely if the feature is not operationally required
- Audit existing sessions/accounts for any that were resolved via token exchange during the exposure window for signs of cross-issuer identity collisions
Workarounds
- Restrict N8N_TOKEN_EXCHANGE_TRUSTED_KEYS to exactly one trusted issuer
- Temporarily disable the Enterprise token-exchange preview feature
Longer-term hardening
- Enforce composite (iss, sub) identity binding for any custom or third-party OIDC/JWT federation integration, not just n8n
- Require unique, namespaced subject identifiers per issuer in IdP configuration to reduce collision risk even on patched versions
- Monitor n8n audit/auth logs for authentication events where the resolved account's configured issuer differs from the token's actual iss claim
- Apply least-privilege scoping to workflow credentials so a single impersonated identity cannot reach the full breadth of connected services
CVEs associated with CVE-2026-59208
CVE-2026-59208
Weaknesses (CWE) in CVE-2026-59208
Timeline of CVE-2026-59208
- n8n publishes GitHub Security Advisory GHSA-mq3m-f8x3-579w crediting researcher bearsyankees (Strix AI) with responsible disclosure.
- n8n releases fixed versions 2.27.4 and 2.28.1, enforcing composite (iss, sub) identity binding in the token-exchange resolution logic.
- SOCRadar publishes initial blog analysis of CVE-2026-59208.
- CVE-2026-59208 is publicly disclosed; GitHub CNA assigns CVSS 4.0 7.6 (HIGH).
- CISA-ADP adds a vulnrichment assessment for CVE-2026-59208, increasing tracking signal despite no confirmed exploitation.
- NVD publishes its independent CVSS 3.1 score of 6.8 (MEDIUM), diverging from GitHub's CNA score due to differing treatment of the multi-issuer precondition.
- The Hacker News publishes follow-up coverage; no public PoC or in-the-wild exploitation confirmed as of this date.
- TL-Intel Harness ingests CVE-2026-59208 as a tracked skeleton (TL-2026-1436) given CISA-ADP signal despite unconfirmed active exploitation.
Sources cited for CVE-2026-59208
- CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise
- n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
- CVE-2026-59208 record (CVSS vectors, CWE, dates)
- n8n Security Advisory GHSA-mq3m-f8x3-579w
- n8n release n8n@2.27.4 (fix)
- n8n release n8n@2.28.1 (fix)
- NVD entry for CVE-2026-59208
Detection coverage for TL-2026-1436
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1436 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.