Max severity Ni8mare flaw impacts nearly 60,000 n8n instances
ID: 68791606-94e3-5343-8ce8-ba5bd194bc5d
STIX ID: report--68791606-94e3-5343-8ce8-ba5bd194bc5d
Feed Name: Bleeping Computer
Threat Score
A maximum-severity vulnerability (CVE-2026-21858, “Ni8mare”) in the n8n workflow automation platform allows unauthenticated remote attackers to hijack locally deployed instances—potentially exposing secrets, forging sessions, injecting files, or executing commands; researchers reported the flaw and Shadowserver found tens of thousands of exposed, unpatched instances worldwide, and admins are urged to upgrade to n8n 1.121.0+ or restrict public webhook/form endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
