THREAT OPS › Threat News › [NVD] CVE-2026-72772 (HIGH 8.8) — n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the t
[NVD] CVE-2026-72772 (HIGH 8.8) — n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the t
CVE-2026-72772 CVSS: 8.8 HIGH Published: 2026-08-11T13:19:07.623
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the trusted key's permitted role ceiling covered that accou
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-72772cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72772