Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

n8n Token Exchange Flaw Enables Cross‑Issuer Login, Bypassing Issuer Validation

n8n Enterprise incorrectly matched JWTs to local users using only the sub claim, ignoring the issuer. This allowed a token from one trusted issuer to log in as a user from another, creating a credential‑compromise scenario. For SOC 2 auditors, the incident highlights the need for documented, continuously‑monitored access‑control checks around token validation.

LiveThreat™ Intelligence · 📅 July 17, 2026· 📰 thehackernews.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

n8n Token Exchange Flaw Enables Cross‑Issuer Login, Bypassing Issuer Validation

What Happened — n8n’s Enterprise deployment allowed multiple external JWT issuers. The platform matched an incoming token to a local user using only the sub claim and ignored the iss claim. A valid JWT from Issuer A that contained a sub belonging to a user under Issuer B authenticated the attacker as that user, effectively granting unauthorized access.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a gap in SOC 2 Access Control design: authentication logic must enforce both identity (sub) and trust domain (iss).
  • Continuous‑compliance programs need verifiable evidence that token‑validation controls are correctly implemented and monitored.
  • Without documented controls and automated testing, organizations risk audit findings for “Logical Access” and “Identity & Authentication” criteria.

Who Is Affected – SaaS and workflow‑automation providers that integrate n8n Enterprise, as well as any enterprise that has deployed n8n with multi‑issuer SSO configurations.

Recommended Actions

  • Review and harden JWT validation: enforce issuer (iss) verification alongside subject (sub).
  • Apply the vendor‑released patch or upgrade to the latest n8n version.
  • Re‑issue tokens for all users and rotate any secrets used for signing.
  • Map the authentication flow to SOC 2 CC6.1 (Logical Access) and capture evidence of the fix in your continuous‑compliance tooling.

Technical Notes – The flaw stems from a logic error in n8n’s token‑exchange module; no CVE ID has been assigned yet. Exploitation requires a valid JWT from a trusted issuer, making the attack vector a vulnerability exploit rather than phishing or credential theft. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/n8n-token-exchange-flaw-could-let.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →