n8n Token Exchange Flaw CVE-2026-59208 Enables Account Takeover via JWT Sub Claim Mismatch
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…
Strix is an AI penetration testing company whose agent, via GitHub user bearsyankees, discovered the identity binding bug in n8n's token exchange…