Latest n8n vulnerability: CVE-2026-21858 #
Cyera has reported a vulnerability in the n8n workflow automation tool. This flaw allows a remote, unauthenticated attacker to execute arbitrary code on the vulnerable system. Successful exploitation could allow complete system compromise.
This vulnerability has been assigned CVE-2026-21858 and is rated highly critical has a CVSS score of 10.0.
The following versions are affected
- n8n versions 1.65.0 up to but not including 1.121.0
What is n8n? #
n8n is an AI-centric workflow automation tool.
What is the impact? #
Successful exploitation of this vulnerability would allow an adversary to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.
Are updates or workarounds available? #
n8n.io has released version 1.121.0 of n8n. Users are urged to update as quickly as possible.
How to find potentially vulnerable systems with runZero #
From the Services inventory, use the following query to locate potentially vulnerable assets:
_asset.protocol:="http" AND protocol:="http" AND html.title:="n8n.io%"