A critical vulnerability has been identified in the n8n workflow automation platform, affecting versions prior to 1.123.55, 2.25.7, and 2.26.2. The flaw resides in three endpoints used by the Dynamic Credentials feature, which fail to enforce per-resource ownership or scope checks. Authenticated users, even without project membership or credential-sharing relationships, can enumerate credential identifiers, names, and types referenced by private workflows. Additionally, they can initiate OAuth authorization flows against another user's credentials, potentially overwriting stored tokens with those bound to their own session. This enables unauthorized access to sensitive credential information and potential token takeover. The CVSS score of 9.9 reflects the high severity, as this vulnerability could lead to data breaches, unauthorized system access, and disruption of workflow automation processes. All users of affected n8n versions are strongly advised to apply the latest security patches immediately. Organizations should review their access controls and monitor for anomalous activity related to credential management. This issue underscores the importance of timely patching and strict access control enforcement in workflow automation platforms.