logo

New n8n Vulnerability (CVE-2026-21858) Allows Unauthenticated File Access and RCE

ID: aae37295-3dae-5d7e-954c-0524189d0869

STIX ID: report--aae37295-3dae-5d7e-954c-0524189d0869

Feed Name: The Cyber Express

Threat Score
92/100

Date Published: 2026-01-08

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A critical content-type confusion vulnerability (CVE-2026-21858, CVSS 10.0) in the n8n workflow automation platform allows unauthenticated attackers to override file handling in webhooks, read local files (including the internal SQLite database and config), escalate to administrative access and achieve remote code execution; the issue affects versions up to 1.65.0 and was patched in 1.121.0 with users urged to upgrade and restrict public webhook/form endpoints until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.