logo

Ni8mare on Automation Street: When Workflows Turn Into an Attack Path

ID: f4448e8d-fb1e-5104-8eef-1d164b38f5eb

STIX ID: report--f4448e8d-fb1e-5104-8eef-1d164b38f5eb

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
90/100

Date Published: 2026-01-15

Date Updated: 2026-04-28

Author: Nikita Kazymirskyi

...
...

Ni8mare (CVE-2026-21858) is a critical unauthenticated vulnerability in self-hosted n8n that allows attackers to exploit content-type parsing inconsistencies on public webhook/form endpoints to access configuration and cryptographic materials, forge admin sessions, create or modify workflows, and achieve remote code execution and full instance takeover; defenders are urged to upgrade to patched versions, reduce external exposure, rotate stored credentials, and perform compromise assessments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.