logo

CVE-2026-21877: Max-Severity n8n Flaw Allows Authenticated RCE

ID: b0e80786-4bfd-5f0b-81e2-1c9f1c7b63c1

STIX ID: report--b0e80786-4bfd-5f0b-81e2-1c9f1c7b63c1

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2026-21877 is a maximum-severity (CVSS 10.0) authenticated remote code execution vulnerability in n8n that allows an authenticated user to write and trigger attacker-controlled code, affecting n8n versions 0.123.0 up to (but not including) 1.121.3 across self-hosted and cloud deployments; the issue was fixed in n8n 1.121.3 and administrators are advised to patch or apply temporary mitigations to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.