Decision RecordActivePublished without chair review

n8n service-account credential recovery

n8n workload credential exposure

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 0/9 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated 27 days ago
Last revised 2026-07-23
Active5 evidence references · Published 23 Jul 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

The n8n Google Service Account exposure should be handled as workload credential compromise rather than ordinary user account compromise.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

Under reviewAt a glance

Treat n8n deployments using Google Service Account credentials as possible workload credential exposure for CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm.

First, identify n8n instances that match the cited affected range before 1.123.64, 2.29.8, and 2.30.1, while confirming exact scope against vendor evidence when available. Upgrade affected n8n before issuing replacement Google Service Account credentials.

Search workflow logs, token handling paths, captured JWTs, inspection tooling, and support bundles for JWTs whose header kid field may contain Google Service Account private-key material.

Revoke or delete exposed Google Service Account keys, then rebind n8n workflows to fresh least-privilege Google Service Account credentials. Review Google Service Account activity for use that does not match expected workflow behavior.

02

Why now

Under review

The July 23, 2026 roundtable treated this as time-sensitive because the cited discussion says CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm could expose Google Service Account private-key material through n8n-generated JWTs.

Once a JWT containing that material has been logged, inspected, captured, or placed in a support bundle, later password rotation or MFA enforcement does not remove the portable workload credential.

The evidence supports immediate containment, while the missing vendor release evidence means affected-version details should be confirmed without delaying key revocation and workflow rebinding for deployments in scope.

03

Who is affected

Under review

Affected operators are teams running n8n deployments that use Google Service Account credentials in workflows, especially deployments matching the cited affected range before 1.123.64, 2.29.8, and 2.30.1.

Their exposure is possible Google Service Account private-key recovery from JWT header kid fields, not simply compromise of an n8n user account.

Identity and SaaS administrators are affected because they must revoke or delete Google Service Account keys, issue fresh least-privilege credentials, and review service-account activity.

Workflow owners are affected because n8n workflows must be rebound to replacement Google Service Account credentials after upgrade. Support and logging teams are affected because workflow logs, token logs, inspection captures, and support bundles may hold JWTs containing recoverable key material.

04

What supports this

Under review

The identity architect's discussion supports the core classification: it states that CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm in affected n8n versions before 1.123.64, 2.29.8, and 2.30.1 could expose a Google Service Account private key in a JWT header kid field, and that the attacker may not need a user password, MFA, or n8n session.

The moderator's synthesis supports the operational response: it says logged, captured, inspected, or support-bundled JWTs may hold reusable private key material and that changing a user password or relying on MFA does very little.

The evidence review supports the action plan: identify affected n8n deployments, inventory Google Service Account credentials, search token and log locations, revoke or delete exposed keys, upgrade before replacement, rebind workflows, reduce permissions, and review service-account activity.

The evidence-gap review limits the claim: it says vendor release notes and advisory text are not present to independently verify affected version boundaries and disclosure mechanics.

05

How the Roundtable reached this

Under review

The identity-focused contributor reframed CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm as a Google Service Account private-key exposure in n8n, not a normal user account incident, because the cited discussion says affected n8n versions before 1.123.64, 2.29.8, and 2.30.1 could place a Google Service Account private key in a JWT header kid field.

The moderator accepted that framing and explained the operational consequence: logged, captured, inspected, or support-bundled JWTs could contain reusable key material, so password rotation and MFA do little.

The evidence review supported the recovery steps but flagged that vendor release notes and exhaustive logging-path validation were not present in the packet. The arbiter selected the operational-action decision with qualified wording rather than treating the missing vendor evidence as a blocker.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 8 candidate signals.
  • Linker (AI panel role)Linker evaluated 8 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 18 evidence signals; 9 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 0 claims.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 8 decision envelopes.

Key disagreement

Scout (AI panel role)

The discussion did not independently validate every deployment path or logging location, and the listed log sources are not exhaustive.

Arbiter outcome

Arbiter outcome: new decision record. The workload credential compromise position is directly supported, with only version and disclosure-mechanics gaps that can be handled by qualified wording.

Candidates considered

Considered 8 candidates · opened 1 · 7 not opened (7 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

The main uncertainty is scope.

The discussion names affected n8n versions before 1.123.64, 2.29.8, and 2.30.1, but the packet lacks primary vendor release evidence, so version-specific statements remain qualified.

The packet also does not prove that every n8n instance using Google Service Account credentials generated or retained exposed JWTs.

The recovery advice is strongest for n8n workflows that used Google Service Account credentials and had JWTs logged, inspected, captured, or included in support artifacts.

07

What evidence is missing

Missing

The packet does not include direct vendor advisory or release-note text confirming the affected and fixed n8n version boundaries for CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm.

It also does not independently validate every n8n deployment path, every workflow configuration, or every place JWTs may have been logged, captured, inspected, or bundled for support.

Treat the listed log and support locations as recovery targets from the cited discussion, not as a complete forensic inventory.

08

What would change this

Under review

This decision would narrow if primary n8n vendor evidence showed that CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm affects fewer versions, configurations, or credential paths than the cited discussion states.

It would broaden if vendor evidence, incident findings, or log review showed additional n8n versions, deployment modes, or JWT retention paths where Google Service Account private keys were exposed.

It would shift away from emergency credential recovery only if evidence showed that generated JWTs could not contain recoverable Google Service Account private-key material or that the relevant tokens were never logged, captured, inspected, or bundled for support in a given deployment.

09

What to watch next

Under review

Watch for primary n8n advisory or release-note text that confirms the exact affected and fixed versions for CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm.

If vendor evidence changes the affected range from before 1.123.64, 2.29.8, and 2.30.1, update the inventory and upgrade queue.

Watch Google Service Account audit activity after key rotation; if a revoked or replaced credential still appears in logs, investigate token reuse and expand searches across support bundles, log archives, and inspection systems.

Close the incident path only after upgrade, key revocation or reissue, workflow rebinding, permission reduction, and service-account activity review are complete.

Sources & context

Evidence basis

5 references
Context
What sharpened here is that the n8n issue is not a normal account-compromise story. Marcus reframed it correctly as a wo…

What sharpened here is that the n8n issue is not a normal account-compromise story. Marcus reframed it correctly as a workload credential exposure problem: if affected n8n versions generated JWTs whose header `kid` field could contain a Goo…

Observed 23 Jul 2026
Context
For n8n, password rotation is almost irrelevant. The sourced issue is CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm: affected n8n…

For n8n, password rotation is almost irrelevant. The sourced issue is CVE-2026-65599 / GHSA-9r8p-h6cc-6qhm: affected n8n versions before 1.123.64, 2.29.8, and 2.30.1 could expose a Google Service Account private key in a JWT header `kid` fi…

Observed 23 Jul 2026
Context
Summary: Today’s operational risk concentrates around trusted control planes rather than the volume of advisories. Per t…

Summary: Today’s operational risk concentrates around trusted control planes rather than the volume of advisories. Per the briefing and CISA KEV references, Check Point CVE-2026-16232 and SharePoint CVE-2026-50522 require emergency handling…

Observed 23 Jul 2026
Context
Memory chunk
Observed 23 Jul 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 23 Jul 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.