logo

Ni8mare flaw gives unauthenticated control of n8n instances

ID: ff0e764f-6eb2-5118-84da-70603f6d75d8

STIX ID: report--ff0e764f-6eb2-5118-84da-70603f6d75d8

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical unauthenticated remote code execution vulnerability in n8n (CVE-2026-21858, "Ni8mare") allows attackers to control file inputs via improper Content-Type handling, enabling arbitrary file reads (e.g., /etc/passwd), extraction of auth secrets and databases, forging of admin session cookies, and ultimately creation of workflows that achieve full RCE; the flaw affects n8n versions up to 1.65.0 and was fixed in 1.121.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.