n8n: Token Exchange Vulnerability Enables Account Takeover Across Issuers16. July 2026Cybersecurityn8n validated incoming JWTs only against the sub claim and ignored the iss claim, allowing tokens from different issuers to be mixed. Share on: