logo

Max severity Ni8mare flaw lets hackers hijack n8n servers

ID: 0e442230-030d-5856-aecb-e0d1777d86f6

STIX ID: report--0e442230-030d-5856-aecb-e0d1777d86f6

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A maximum-severity vulnerability dubbed "Ni8mare" (CVE-2026-21858) in the n8n workflow automation platform allows unauthenticated attackers to exploit a content-type parsing bug to read arbitrary files, expose stored secrets, forge sessions, and potentially execute commands; researchers estimate over 100,000 vulnerable instances. n8n recommends updating to version 1.121.0 or later and restricting public webhook/form endpoints as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.