logo

CRITICAL ALERT: Critical Unauthenticated Remote Code Execution vulnerability in n8n workflow automation platform

ID: 9d56f712-7a9e-5cf7-9db9-840b4ef28d9b

STIX ID: report--9d56f712-7a9e-5cf7-9db9-840b4ef28d9b

Feed Name: ASD's ACSC - Alerts RSS

Threat Score
75/100

Date Published: 2026-01-08

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

A critical unauthenticated Remote Code Execution vulnerability (CVE2026-21858) affects n8n versions 1.65.0 and earlier, allowing attackers to read files via form-based workflows and escalate to full RCE. Organisations are advised to upgrade to n8n 1.121.0 or later, avoid exposing instances to the internet, require authentication for Forms, and temporarily restrict or disable public webhook/form endpoints until patched; contact 1300 CYBER1 for assistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.