A medium-severity vulnerability affecting n8n versions >= 2.28.0, < 2.28.1 affecting n8n versions < 2.27.4, identified as CVE-2026-59254 with a CVSS score of 6.3, affects instances configured to use the external secrets feature where an authenticated user with project editor access can read plaintext values of external secrets by referencing them in a node expression without needing explicit secrets access permissions. This flaw type is categorized under CWE-639 and can be exploited via workflow expressions outside credentials, posing a significant business impact as it allows unauthorized access to sensitive information.
We recommend you to update n8n to version 2.28.1 or 2.27.4.[/subscribe_to_unlock_form]
A medium-severity vulnerability affecting n8n versions >= 2.28.0, < 2.28.1 affecting n8n versions < 2.27.4, identified as CVE-2026-59254 with a CVSS score of 6.3, affects instances configured to use the external secrets feature where an authenticated user with project editor access can read plaintext values of external secrets by referencing them in a node expression without needing explicit secrets access permissions. This flaw type is categorized under CWE-639 and can be exploited via workflow expressions outside credentials, posing a significant business impact as it allows unauthorized access to sensitive information.
We recommend you to update n8n to version 2.28.1 or 2.27.4.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]