CVE-2026-33696 turns anyone who can create or edit an n8n workflow into remote code execution as the n8n process user. That should bother you even if you trust your editors, because the n8n process holds the encryption key for every credential stored in the instance. RCE here is not a foothold.
Source: [Dev.to](https://dev.to/secbyjasonmiller/one-proto-away-from-losing-every-credential-in-your-n8n-instance-1m5p)