Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-54052.

Upgrade to Pro
CVE-2026-54052 Elastic Security · Elastic

Detect n8n-MCP Cross-Tenant Workflow Backup Access (CVE-2026-54052) in Elastic Security

Detects exploitation of CVE-2026-54052, an authorization bypass (CWE-639/CWE-862) in n8n-mcp <= 2.56.0 HTTP multi-tenant deployments allowing cross-tenant access to workflow version backups. Attackers manipulate tenant/workflow identifiers in backup retrieval requests to read another tenant's stored workflow versions, which may contain embedded credentials, API keys, and webhook secrets.

MITRE ATT&CK

Tactic
Initial Access Credential Access Collection

Elastic Detection Query

Elastic Security (Elastic)
eql
sequence by http.client_ip with maxspan=15m
  [network where url.path : ("*workflow*", "*backup*") and url.path : ("*version*", "*history*") and url.query : "*tenant*"]
  [network where url.path : ("*workflow*", "*backup*") and url.path : ("*version*", "*history*") and url.query : "*tenant*"]
  [network where url.path : ("*workflow*", "*backup*") and url.path : ("*version*", "*history*") and url.query : "*tenant*"]
critical severity medium confidence

Detects a sequence of three or more workflow/backup version requests carrying tenant query parameters from the same client IP within 15 minutes, suggesting cross-tenant backup access attempts.

Data Sources

HTTP Proxy LogsWeb Server Logs

Required Tables

logs-*

False Positives & Tuning

  • Repeated legitimate requests from a shared corporate NAT/proxy IP
  • Automated backup verification jobs iterating tenants under authorized admin context
  • Browser prefetching or retry behavior generating duplicate requests

Other platforms for CVE-2026-54052


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Cross-tenant backup retrieval via tenant parameter manipulation

    Expected signal: HTTP GET request to /api/mcp/workflows/backup/version with tenant_id query parameter that does not match the bearer token's authenticated tenant claim, logged in reverse proxy / application access logs

  2. Test 2Enumeration of multiple tenant workflow backups

    Expected signal: Four or more HTTP requests to the backup/history endpoint from a single source IP within seconds, each carrying a distinct tenant_id value

  3. Test 3Credential harvesting from exposed workflow backup content

    Expected signal: Same cross-tenant HTTP request as the retrieval test, plus process execution logs showing local parsing/grepping of the downloaded backup file for credential-like strings

Unlock playbooks & atomic tests with Pro

Get the full detection package for CVE-2026-54052 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.

df00tech Pro — £29/user/month

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections