What happened
n8n published its bi-weekly security update on 2026-10-01: 14 advisories, 10 rated High. CVE-2026-103246 (CVSS 7.7, HIGH) documents that n8n fails to validate credential ownership during inline agent node-tool introspection, letting an attacker reference arbitrary credential IDs and decrypt/exfiltrate plaintext secrets. The same batch fixes credential checks for shared/nested workflows, an unauthenticated unbounded OAuth client-persistence via the authorize endpoint, stored XSS in the Chat Trigger, an HMAC bypass on human-in-the-loop approvals, and an MCP workflow-validation prototype-mutation path to owner-account takeover.
Why it matters
n8n workflows exist precisely to hold secrets and automate LLM/agent operations; the new agent features (MCP, tool approvals, agent nodes) attracted the most severe bugs. A single low-privilege user can pull every credential a production agent workflow uses to call real systems, and the MCP validator path reaches owner-level takeover — credential theft and agent-platform compromise of a widely-deployed system, warranting Tier A.
Attack vector
A low-privilege editor can reference arbitrary credential IDs during inline agent node-tool introspection to decrypt and exfiltrate plaintext secrets (API keys, OAuth tokens, DB passwords) to an attacker-controlled host (CVE-2026-103246). Companion advisories cover an unauthenticated OAuth client-persistence flaw, a stored XSS in the Chat Trigger, Send-and-Wait HMAC bypass (unauthenticated approval of waiting executions), and an MCP workflow-validation prototype mutation allowing owner-account takeover.
Affected systems
n8n < 1.123.83 (v1), < 2.41.4 (v2 stable), < 2.42.1 (v2 beta); CVE-2026-103246 affects < 2.39.6 and 2.40.0-2.40.1
Mitigation
Upgrade self-hosted to n8n 1.123.83+, 2.41.4+, or 2.42.1+. No cloud action needed. Back up N8N_ENCRYPTION_KEY before upgrade.