Researchers rush to warn defenders of max
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21858 +1 in the same advisory: …21877 | Unauthenticated RCE in n8n Workflow Automation (Ni8mare) n8n versions 1.65.0 through below 1.121.0 contain an input-validation flaw (CWE-20) in the handling of certain form-based workflows, allowing an unauthenticated remote attacker to reach the underlying server through form endpoints. By triggering a vulnerable form workflow, the attacker can access files on the host and expose sensitive information stored there; the Cyera research team (which named the bug "Ni8mare") and the CVSS 10.0 score with high integrity impact indicate this yields unauthenticated remote code execution and potential full takeover. Any self-hosted n8n instance running an affected version that exposes form-based workflows over the network is at risk, with blast radius amplified by n8n's typical access to credentials, secrets, and connected internal systems. The issue is fixed in version 1.121.0; the flaw is not yet in CISA's KEV, but a public proof-of-concept is available and EPSS assigns a 78.4% probability of exploitation within 30 days, so defenders should treat exploitation as likely and imminent. Do: Upgrade n8n to version 1.121.0 or later immediately. If you cannot upgrade right away, check whether any workflows use form triggers and remove those form endpoints from untrusted network exposure — place them behind authentication, a reverse proxy, or an IP allowlist. Review instance logs for unexpected requests to form/webhook paths and unusual file access, given the high EPSS score and public proof-of-concept. | 10.0 group max | 78% | PoC ×2 |
| large≈50,000–100,000 internet-exposed n8n servers (self-hosted automation platform, affected range spans roughly a year of releases) |
Full article679 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Roughly 100,000 servers running the automated workflow platform for AI and other enterprise tools are potentially exposed to exploitation.
Listen to this article
0:00
Learn more.
Researchers warn that a critical vulnerability in n8n, an automation platform that allows organizations to integrate AI agents, workflows and hundreds of other enterprise services, could be exploited by attackers to achieve full control of targeted networks.
The maximum-severity vulnerability — CVE-2026-21858 — affects about 100,000 servers globally, according to Cyera, which initially discovered and reported the defect to n8n on Nov. 9. Developers responsible for the widely used platform released a patch for the vulnerability on Nov. 18, but didn’t publicly disclose or assign the vulnerability a CVE until Wednesday.
“The risk is massive,” Dor Attias, security researcher at Cyera Research Labs, told CyberScoop. “n8n sits at the heart of enterprise automation infrastructure. Gaining control of n8n means gaining access to your secrets, customer data, CI/CD pipelines and more.”
Researchers haven’t observed active exploitation of the vulnerability, but Cyera published a working proof of concept, which typically triggers a race for defenders to patch a defect before in-the-wild exploitation occurs.
“We are seeing a noticeable increase in traffic targeting customer n8n instances,” Upwind CEO Amiram Shachar said. “We believe this activity is likely driven by heightened interest from both attackers and security researchers rather than confirmed exploitation — at least for now.”
The content-type confusion vulnerability requires no authentication, allows full remote-code execution and there is no workaround. Researchers and n8n, which did not respond to a request for comment, advise users to update to version 1.121.1 or later to remediate the vulnerability.
Cyera, which dubbed the defect “ni8mare,” said the patch effectively addresses the vulnerability.
Threat hunters are especially concerned about the vulnerability because of the widespread deployment of n8n and the potential exposure that could occur as a result of exploitation.
“n8n instances typically manage highly sensitive workflows containing access tokens, credentials and business-critical data. That makes them a gold mine for attackers,” Shachar said.
Systemic weaknesses, including a lack of proper exposure management, permission boundaries and broader application security control amplify the risk, Shachar added.
It’s unclear why n8n took almost two months to publicly disclose the vulnerability. The company acknowledged and started working on a fix for the defect a day after Cyera reported the vulnerability, Attias said.
“The delay was likely due to them working on patching additional bugs, which is more important than rushing to publish the advisory,” he added.
Indeed, n8n disclosed a separate remote-code execution vulnerability — CVE-2026-21877 — with a CVSS rating of 10 on Wednesday.
Shachar said disclosure procedures and the rapid growth of n8n could have slowed coordination with security advisory channels, adding that some security teams view delayed disclosures as a responsible measure to reduce the risk of immediate, widespread attacks.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/n8n-critical-vulnerability-massive-risk/