logo

CVE-2026-21858 aka Ni8mare: Critical Unauthenticated Remote Code Execution Vulnerability in n8n Platform

ID: a6c0d0c4-c0b2-560b-b5ed-e6365192bed6

STIX ID: report--a6c0d0c4-c0b2-560b-b5ed-e6365192bed6

Feed Name: SOC Prime Blog

Threat Score
85/100

Date Published: 2026-01-09

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Ni8mare (CVE-2026-21858) is a critical (CVSS 10.0) unauthenticated vulnerability in n8n’s webhook/form parsing that allows attackers to overwrite the req.body.files object and cause the application to copy arbitrary local files into persistent storage, enabling sensitive data exposure, workflow manipulation, credential compromise, and in some configurations full instance compromise; it affects n8n versions up to and including 1.65.0 and was fixed in 1.121.0 (released 2025-11-18). Censys reports roughly 26,500 internet-accessible n8n hosts, increasing the potential attack surface, and no official workaround exists other than restricting public endpoints until patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.