{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/embed-login/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (\u003c 2.31.5)","n8n (\u003e= 2.32.0, \u003c 2.32.1)","n8n (2.32.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","account-takeover","n8n","embed-login","credential-access","exfiltration","rce","sandbox-escape","javascript"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eA high-severity authentication bypass vulnerability has been identified in the workflow automation platform n8n, affecting versions prior to 2.31.5 and between 2.32.0 and 2.32.1. This flaw, present when the embed login feature is enabled and at least one trusted key source is configured, allows an attacker to achieve full account takeover. Specifically, if a trusted identity provider issues tokens containing unverified email claims, n8n's token exchange mechanism fails to validate that the trusted key's permitted role ceiling covers the account or that the email claim itself is verified. This oversight enables an adversary to forge or intercept a validly-signed token from such an issuer and authenticate as any existing n8n user by matching the unverified email claim to a local account. This vulnerability poses a critical risk to data integrity and access control for affected n8n instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Reconnaissance:\u003c/strong\u003e Attacker identifies a vulnerable n8n instance with the embed login feature enabled and at least one trusted key source configured.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrusted Issuer Identification:\u003c/strong\u003e Attacker identifies a configured trusted identity provider that issues tokens which include unverified email claims.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eToken Acquisition/Forgery:\u003c/strong\u003e Attacker obtains a validly-signed token from the identified trusted issuer, potentially by exploiting a weakness in the issuer itself or by crafting a token with an unverified email claim matching an existing n8n user.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpersonation Attempt:\u003c/strong\u003e The attacker presents this specially crafted token to the n8n instance's embed login endpoint, claiming the identity of an existing n8n user via the unverified email claim.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Bypass:\u003c/strong\u003e Due to the vulnerability, n8n fails to verify the email claim's validity or the trusted key's role ceiling against the target account, and mistakenly authenticates the attacker.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAccount Takeover:\u003c/strong\u003e The attacker gains full control over the targeted n8n user's account, including access to workflows, data, and configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact on Target:\u003c/strong\u003e Attacker can now execute arbitrary workflows, exfiltrate sensitive data, or disrupt business operations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to full account takeover within the n8n instance. An attacker can authenticate as any existing user, gaining access to all their associated data, workflows, and permissions. This can result in unauthorized data access, modification, or deletion, as well as the execution of malicious automation workflows. The risk is specifically present for n8n instances where the embed login feature is enabled and at least one trusted key source is configured, particularly if those trusted keys are associated with identity providers that emit unverified email addresses.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances to version 2.32.1 or later immediately to remediate the vulnerability.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrade is not possible, disable the embed login feature by setting the environment variable \u003ccode\u003eN8N_TOKEN_EXCHANGE_ENABLED=false\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eIf embed login cannot be disabled, restrict network access to the n8n instance to fully trusted parties only.\u003c/li\u003e\n\u003cli\u003eAudit all configured trusted keys and their \u003ccode\u003eallowedRoles\u003c/code\u003e assignments for any unnecessarily broad permissions.\u003c/li\u003e\n\u003cli\u003eReview \u003ccode\u003eauth_identity\u003c/code\u003e records for unexpected \u003ccode\u003etoken-exchange\u003c/code\u003e entries, especially those linked to high-privilege accounts, as a post-compromise indicator.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T22:18:03Z","date_published":"2026-07-22T22:05:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-unverified-email-claim-auth-bypass/","summary":"A high-severity vulnerability in n8n's embed login feature (CVE-2026-XXXX) allows attackers to achieve full account takeover by leveraging unverified email claims in incoming tokens, enabling authentication as any existing user if the instance has embed login enabled and a trusted key source configured that emits unverified email addresses.","title":"n8n Account Takeover via Unverified Email Claim in Token Exchange Embed Login","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-unverified-email-claim-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Embed-Login","version":"https://jsonfeed.org/version/1.1"}