CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59254

mediumcovered by 2 sourcesfirst seen 2026-07-15
Impact External secrets were incorrectly resolved in workflow node expressions, where they are not intended to be available. An authenticated user with project editor access could read the plaintext value of external secrets by referencing them in a node expression, without needing explicit secrets access permissions. This issue only affects instances with the external secrets feature configured. Patches The issue has been fixed in n8n versions 2.27.4 and 2.28.1. Users should upgrade to one of these versions or later to remediate the vulnerability. Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict project membership to fully trusted users only. - Avoid granting editor access to projects on instances where external secrets are configured. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

⚡ Watch CVE-2026-59254

Get an email if CVE-2026-59254 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-59254

CVE.org record

Embed the live status

CVE-2026-59254 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59254 status](https://www.csirts.com/badge/CVE-2026-59254)](https://www.csirts.com/cve/CVE-2026-59254)