logo

Max severity Ni8mare flaw impacts nearly 60,000 n8n instances

ID: 68791606-94e3-5343-8ce8-ba5bd194bc5d

STIX ID: report--68791606-94e3-5343-8ce8-ba5bd194bc5d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A maximum-severity vulnerability (CVE-2026-21858, “Ni8mare”) in the n8n workflow automation platform allows unauthenticated remote attackers to hijack locally deployed instances—potentially exposing secrets, forging sessions, injecting files, or executing commands; researchers reported the flaw and Shadowserver found tens of thousands of exposed, unpatched instances worldwide, and admins are urged to upgrade to n8n 1.121.0+ or restrict public webhook/form endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.