# CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token Exchange

> n8n Enterprise's token-exchange feature resolves external identities using only the JWT `sub` claim while ignoring the `iss` claim, letting a holder of a valid token from one trusted issuer impersonate any account whose subject value matches under a second trusted issuer. Requires Enterprise token exchange enabled with 2+ trusted issuers configured; affects n8n < 2.27.4 and 2.28.0, fixed in 2.27.4 and 2.28.1.

- **Published:** 2026-07-17T00:00:00Z
- **Last reviewed:** 2026-07-17T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1436
- **ID:** TL-2026-1436
- **Severity:** HIGH (CVSS 7.6)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-59208

## Description

CVE-2026-59208 is an improper-authentication / origin-validation vulnerability (CWE-287, CWE-346) in n8n's Enterprise-only, preview-flagged token-exchange capability, activated via the `N8N_TOKEN_EXCHANGE_TRUSTED_KEYS` configuration. RFC 7519 specifies that a JWT subject (`sub`) identifier is guaranteed unique only within the context of its issuing authority (`iss`); correct identity binding therefore requires the composite `(iss, sub)` pair. n8n's token-exchange identity-resolution logic instead matched external identities to local accounts using the `sub` claim alone.

In a deployment configured to trust two or more external token issuers (a supported pattern for OEM/white-label partner integrations), an attacker who can obtain a valid, properly signed JWT from ANY one of the trusted issuers can present it to n8n. If that token's `sub` value happens to collide with (or is deliberately crafted/obtained to match) the `sub` of a victim account registered under a DIFFERENT trusted issuer, n8n resolves the token to the victim's local account and issues that victim's session — full account takeover with no password, MFA bypass, or credential theft required against the victim directly. The attacker only needs standing as a legitimate user of any one trusted issuer plus knowledge (or a guess) of a colliding subject identifier.

Exploitation is entirely configuration-gated: single-issuer n8n deployments, deployments that do not enable Enterprise token exchange, and deployments with only one trusted issuer are not exposed. This preconditions-heavy nature explains the scoring divergence between GitHub's CNA (CVSS 4.0, 7.6/HIGH, emphasizing high confidentiality/integrity impact once conditions are met) and NVD (CVSS 3.1, 6.8/MEDIUM, emphasizing the high attack-complexity precondition of a multi-issuer configuration). n8n shipped fixes in 2.27.4 and 2.28.1 on 2026-06-24, ahead of the CVE's public disclosure on 2026-07-09 and CISA-ADP vulnrichment assessment on 2026-07-13. As of 2026-07-16 there is no public PoC and no confirmed in-the-wild exploitation; the vulnerability was responsibly disclosed by researcher bearsyankees (affiliated with Strix AI) via GitHub Security Advisory GHSA-mq3m-f8x3-579w.

Impact once exploited: because n8n workflows routinely hold stored credentials for third-party SaaS/cloud/database connections, an attacker who impersonates a victim account inherits that victim's workflow access — enabling data collection from connected services, modification/creation of automations (including ones that exfiltrate data over the workflow's own outbound HTTP nodes), and lateral movement into every system the victim's n8n identity is authorized to reach.

## MITRE ATT&CK

- T1595 Active Scanning
- T1590 Gather Victim Network Information
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1550 Use Alternate Authentication Material
- T1606 Forge Web Credentials
- T1087 Account Discovery
- T1213 Data from Information Repositories
- T1567 Exfiltration Over Web Service
- T1565 Data Manipulation

## Sources

- [CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise](https://socradar.io/blog/cve-2026-59208-cross-issuer-impersonation-n8n/)
- [n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer](https://thehackernews.com/2026/07/n8n-token-exchange-flaw-could-let.html)
- [CVE-2026-59208 record (CVSS vectors, CWE, dates)](https://cve.threatint.com/CVE/CVE-2026-59208)
- [n8n Security Advisory GHSA-mq3m-f8x3-579w](https://github.com/n8n-io/n8n/security/advisories/GHSA-mq3m-f8x3-579w)
- [n8n release n8n@2.27.4 (fix)](https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4)
- [n8n release n8n@2.28.1 (fix)](https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1)
- [NVD entry for CVE-2026-59208](https://nvd.nist.gov/vuln/detail/CVE-2026-59208)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1436
