n8n disclosed CVE-2026-59208, an improper authentication flaw in the Enterprise token exchange feature that can let a user with a valid JWT from one trusted external issuer be logged into another user’s local account. The bug stems from n8n matching identities only on the JWT sub claim while ignoring the iss claim, creating a cross-issuer collision risk when multiple trusted issuers are configured and subject values overlap. Successful exploitation could give an attacker the victim’s n8n permissions, including access to workflows, stored credentials, and connected business systems.
The issue affects Enterprise deployments using token exchange with at least two trusted external issuers configured, including versions earlier than 2.27.4 on the 2.27 branch and 2.28.0 on the 2.28 branch. n8n fixed the flaw in 2.27.4 and 2.28.1 on June 24, and public reporting said there was no confirmed active exploitation or public proof-of-concept as of July 16. Organizations are advised to upgrade immediately, review trusted issuer settings, validate issuer-to-user binding after patching, and, if patching is delayed, reduce configurations to a single issuer or disable token exchange temporarily.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
As of this date, reporting stated there was no confirmed active exploitation of CVE-2026-59208 and no public proof-of-concept available. CISA was also noted as having no known exploitation recorded.
The authentication flaw was publicly disclosed as CVE-2026-59208. Public reporting described how a valid token from one trusted issuer could be mapped to a user from another issuer when subject values collided.
n8n fixed the cross-issuer impersonation flaw in its Enterprise token exchange feature by releasing versions 2.27.4 and 2.28.1. The issue affected deployments that trusted multiple external JWT issuers and matched users only on the JWT subject claim.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesocradar.io
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.