logo

Ni8mare on Automation Street: When Workflows Turn Into an Attack Path

ID: 2dd3c7c7-2765-564f-8979-b458ef0bd1e2

STIX ID: report--2dd3c7c7-2765-564f-8979-b458ef0bd1e2

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
95/100

Date Published: 2026-01-15

Date Updated: 2026-04-28

Author: Nikita Kazymirskyi

...
...

Ni8mare (CVE-2026-21858) is a critical, unauthenticated vulnerability in self-hosted n8n that leverages content-type parsing inconsistencies on public webhook/form endpoints to access configuration and cryptographic material, forge administrative sessions, and achieve remote code execution through workflow nodes; the advisory urges immediate upgrades (n8n 1.121.0+), reduction of external exposure, credential rotation, and comprehensive compromise assessments to mitigate likely rapid weaponization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.