CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2695

As cited

Copy frozen at (site build).

vulnerabilities

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

n8n, a workflow automation platform, contained a JWT validation flaw in Enterprise instances configured with multiple external token issuers. The vulnerability allowed an attacker with a valid token from one issuer to gain unauthorized access to another user's account by exploiting weak claim matching that validated only the subject (sub) claim while ignoring the issuer (iss) claim.

Why it matters: Enterprise customers using n8n with multiple federated identity providers face account takeover risk; teams should audit token issuer configurations and apply fixes immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary