logo

Maximum Severity “Ni8mare” Bug Lets Hackers Hijack n8n Servers

ID: a45cc5d5-a423-51ae-a993-9b51a946f6c0

STIX ID: report--a45cc5d5-a423-51ae-a993-9b51a946f6c0

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

...
...

Ni8mare (CVE-2026-21858) is a critical, unauthenticated remote vulnerability in the n8n workflow automation platform (CVSS 10.0) that arises from improper handling of webhook content types and parsers, allowing attackers to control file metadata and paths to read local files, exfiltrate secrets, forge session cookies, and potentially achieve remote code execution; users are urged to upgrade to n8n 1.121.0 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.