CVE-2026-59208 is an improper authentication and identity-binding vulnerability in n8n Enterprise deployments that use the token exchange feature with multiple trusted external JWT issuers. In affected versions, n8n resolved an external identity to a local account using only the JWT subject claim (sub) and failed to bind that identity to the issuer claim (iss). Because JWT subject values are only unique within the context of an issuer, two different trusted issuers can legitimately produce the same sub value. Under those conditions, a cryptographically valid token from one trusted issuer could be incorrectly mapped to a local user associated with another trusted issuer. The flaw affects versions prior to 2.27.4 on the 2.27 branch and version 2.28.0, and was fixed in 2.27.4 and 2.28.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
sub values collide. This can grant the attacker an authenticated session as the victim user, inheriting that user’s n8n permissions and access to workflows, credentials, and connected business systems reachable through the impersonated account. The vulnerability does not require the victim’s password and does not depend on bypassing JWT signature verification; it occurs during post-validation identity mapping.If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper authentication vulnerability in n8n Enterprise token exchange where identity resolution used only the JWT subject claim (sub) and not the issuer claim (iss), enabling cross-issuer impersonation in multi-issuer deployments.
An improper authentication and identity-binding vulnerability in n8n Enterprise token exchange where external identities were resolved using only the JWT subject claim (sub) without binding it to the issuer claim (iss), enabling cross-issuer impersonation in multi-issuer deployments.
An authentication/identity-binding flaw in n8n Enterprise token exchange where JWTs were matched to local users using only the sub claim and not the issuer (iss), allowing cross-issuer account impersonation when multiple trusted issuers were configured.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.