THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pq6c-vh67-xpm3 (medium) — n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check

[GHSA] GHSA-pq6c-vh67-xpm3 (medium) — n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check

medgithub_advisoriesPublished 2026-09-10

GHSA-pq6c-vh67-xpm3 Severity: medium CVE: CVE-2026-86993

n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check

## Impact

A log streaming event destination may reference a generic HTTP credential, and the destination resolved and decrypted whichever credential it named without checking that the caller had access to it. A user holding a custom global role

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pq6c-vh67-xpm3