logo

Ni8mare Flaw in n8n: What Defenders Need to Know About CVE-2026-21858

ID: 8c2d36f7-7ec2-5112-b1d4-b486d12f0868

STIX ID: report--8c2d36f7-7ec2-5112-b1d4-b486d12f0868

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-01-08

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Ni8mare (CVE-2026-21858) is a maximum-severity (CVSS 10.0) unauthenticated vulnerability in n8n that lets attackers exploit a Content-Type parsing mismatch to read arbitrary files, bypass authentication, and achieve remote code execution; organizations should upgrade to n8n v1.121.0 or later, avoid exposing instances to the internet, and review file-handling workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.