Debate

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Iniciado por The Hacker News · 20 jul 2026 17:44 · 2 Visitas · 0 Respuestas
Autor del tema #0
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss.

A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in as them. Their password never

Okumaya devam et...

Debes haber iniciado sesión para responder.

0 citas seleccionadas