n8n token-exchange identity binding flaw fixed
🔒 n8n's Enterprise token-exchange feature matched incoming JWTs to local users using only the sub claim and ignored the iss value, allowing a valid token from one issuer to authenticate as a user belonging to another issuer. The bug (CVE-2026-59208) was fixed on June 24 and credited to GitHub user bearsyankees. It only affects Enterprise instances with token exchange enabled and trusting multiple issuers; the recommended mitigations are upgrade to 2.27.4/2.28.1+ or restrict trusted issuers.
