n8n Token Exchange Flaw CVE-2026-59208 Enables Account Takeover via JWT Sub Claim Mismatch
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…
NVD assigned CVE-2026-59208 a CVSS 3.1 score of 6.8 (medium) with CWE-287 and CWE-346, and has not issued a CVSS 4.0 assessment.