Thehackernews Leaked n8n API Keys Lead to Encryption Key Compromise
Article Content
- •Leaked n8n API keys can lead to the compromise of critical encryption keys.
- •CVE-2026-25053 allows escalation from API key access to encryption key theft.
- •129 instances of n8n were found using known weak encryption keys.
A security analysis revealed that leaked n8n API keys can lead to the compromise of the N8N_ENCRYPTION_KEY, which is critical for securing stored credentials and session tokens. The research identified three weaknesses in n8n's trust model, including a flawed derivation method for signing secrets that reduces effective entropy. An attack exploiting CVE-2026-25053 demonstrated how a privileged API key could escalate access to the encryption key. The analysis found 129 instances of n8n using known weak keys, highlighting the risk of credential theft. As of August 2026, n8n has received 48 CVEs since January, with several allowing attackers to escape the workflow execution environment. This situation underscores the vulnerabilities in agentic automation systems, where a single compromised key can have widespread consequences.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-25053 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…