CVE-2026-54052
A flaw in n8n-mcp allows one tenant to see and delete the workflow backups of other tenants when multi‑tenancy is enabled. The bug lets an authenticated user read sensitive data such as credentials and authorization headers from other tenants’ backups. The issue is fixed in version 2.56.1.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
n8n‑mcp versions earlier than 2.56.1 that run with ENABLE_MULTI_TENANT=true.
Real-world impact
An attacker who can log in as a tenant could read other tenants’ workflow history, including credentials and node definitions, and could delete or destroy those backups, potentially causing data loss and exposing sensitive information.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability can be exploited over the network with low effort, requires only low privileges, and changes the scope of the affected system. It grants high confidentiality and integrity impact while only modestly affecting availability, leading to a critical rating.
What to do about it
- 01Upgrade n8n‑mcp to version 2.56.1 or later.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 18d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 18, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/czlonkowski/n8n-mcp/release…release notes
- github.com/czlonkowski/n8n-mcp/securit…mitigationvendor advisory