Maximum-severity n8n flaw lets randos run your automation server
ID: e911b1b5-b1d9-523e-a3f7-ffacfe347799
STIX ID: report--e911b1b5-b1d9-523e-a3f7-ffacfe347799
Feed Name: The Register (Security)
A critical unauthenticated remote code execution vulnerability (CVE-2026-21858, CVSS 10.0) in the n8n automation platform—dubbed “ni8mare”—allows attackers to abuse webhook Content-Type confusion to overwrite internal variables, read arbitrary files and achieve full takeover of vulnerable instances; n8n released a fix in version 1.121.0 but many self-hosted deployments may still be exposed, creating a large blast radius since n8n often stores high-value credentials and integrations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
