logo

Public Exploit Released: Critical n8n Flaw CVE-2026-21858 Exposes 100k Servers

ID: 54b71e07-56a9-5225-ac0b-c943a2dbae48

STIX ID: report--54b71e07-56a9-5225-ac0b-c943a2dbae48

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Ddos

...
...

**Executive Summary:** A critical unauthenticated Content-Type confusion vulnerability (CVE-2026-21858) in n8n enables arbitrary file reads that can be escalated—by extracting the database and config—to forge admin sessions and achieve unauthenticated remote code execution; a public PoC exists and remediation is to upgrade to n8n 1.121.0 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.