CVE-2026-103256
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.
- Published Oct 1, 2026
- CVSS 7.1 high
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available