Public Exploit Released: Critical n8n Flaw CVE-2026-21858 Exposes 100k Servers
ID: 54b71e07-56a9-5225-ac0b-c943a2dbae48
STIX ID: report--54b71e07-56a9-5225-ac0b-c943a2dbae48
Feed Name: securityonline.info
Threat Score
**Executive Summary:** A critical unauthenticated Content-Type confusion vulnerability (CVE-2026-21858) in n8n enables arbitrary file reads that can be escalated—by extracting the database and config—to forge admin sessions and achieve unauthenticated remote code execution; a public PoC exists and remediation is to upgrade to n8n 1.121.0 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
