THREAT OPS › Threat News › [GHSA] GHSA-pq6c-vh67-xpm3 (medium) — n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
[GHSA] GHSA-pq6c-vh67-xpm3 (medium) — n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
GHSA-pq6c-vh67-xpm3 Severity: medium CVE: CVE-2026-86993
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
## Impact
A log streaming event destination may reference a generic HTTP credential, and the destination resolved and decrypted whichever credential it named without checking that the caller had access to it. A user holding a custom global role
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-86993cve
Original source: https://github.com/advisories/GHSA-pq6c-vh67-xpm3