PT-2026-1662 · N8N · N8N
Dorattias
·
Published
2026-01-07
·
Updated
2026-01-09
·
CVE-2026-21858
CVSS v3.1
10
10
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.121.0
Description
n8n is susceptible to a critical vulnerability (CVE-2026-21858), dubbed “Ni8mare,” which allows unauthenticated attackers to achieve remote code execution (RCE). This flaw stems from a content-type confusion vulnerability in the handling of form-based workflows and webhooks. Exploitation enables attackers to read arbitrary files on the server, potentially exposing sensitive information such as API keys, database credentials, and OAuth tokens. Successful exploitation can lead to full system compromise and potentially broader compromise of connected systems. Approximately 100,000 servers are estimated to be exposed. A public proof-of-concept exploit is available, increasing the risk of exploitation.
Recommendations
Upgrade to n8n version 1.121.0 or later immediately.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
CVE-2026-21858
Affected Products
N8N
References · 117
- 🔥 https://github.com/Chocapikk/CVE-2026-21858⭐ 90 🔗 24 · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-21858 · Security Note
- https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg⭐ 167307 🔗 53239 · Note
- https://twitter.com/Cyberciaforge/status/2009343617878692100 · Twitter Post
- https://twitter.com/onyphe/status/2009204899280752719 · Twitter Post
- https://twitter.com/OstorlabSec/status/2009551468332769464 · Twitter Post
- https://twitter.com/PicusSecurity/status/2009234367671947416 · Twitter Post
- https://twitter.com/VulmonFeeds/status/2009149955022192771 · Twitter Post
- https://t.me/thebugbountyhunter/10478 · Telegram Post
- https://twitter.com/greytech_ltd/status/2008979690422165543 · Twitter Post
- https://twitter.com/Horizon3ai/status/2009323569420152965 · Twitter Post
- https://twitter.com/Dhanush_Nehru/status/2009236080365850655 · Twitter Post
- https://twitter.com/UndercodeNews/status/2009223936777834781 · Twitter Post
- https://twitter.com/hanamizuki/status/2009463325181305165 · Twitter Post
- https://twitter.com/e11i0t_/status/2009088699888496971 · Twitter Post