NCSC-2026-0212 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platform
n8n has fixed multiple vulnerabilities in the n8n workflow automation platform, specifically in versions prior to 1.123.55, 2.24.0, 2.25.7, 2.26.1, and 2.26.2. The vulnerabilities affect various components of the n8n platform. Authenticated users with workflow editing rights can bypass Content-Security-Policy (CSP) via the Respond to Webhook node and inject JavaScript via the Chat Trigger node. Furthermore, they can exfiltrate API tokens via the SecurityScorecard node and access, overwrite, or revoke credentials of other users via the Dynamic Credentials feature. Users with editor access to shared workflows can view others' credentials due to insufficient ownership checks. Unauthenticated attackers can submit false payloads via the MicrosoftAgent365Trigger and StripeTrigger nodes, leading to the execution of workflows with malicious data.
CSIRTS triage
- What
- Authenticated users can bypass security policies and exfiltrate sensitive data through various nodes.
- Who is affected
- Authenticated users with workflow editing rights in n8n versions prior to the specified versions.
- Urgency
- Remediation is urgent due to the risk of data exfiltration and unauthorized access to credentials.
- Action
- Upgrade to the specified versions of n8n to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0212
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-543010.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543020.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543040.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543050.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543060.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543070.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543080.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543090.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543100.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543110.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54301 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54302 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54304 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54305 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54306 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54307 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54308 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54309 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54311 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54312 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54313 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54314 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54303 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] n8n: Multiple vulnerabilitiescert-bund
- highGHSA-rm2v-h48j-895m: n8n: SecurityScorecard Node Leaks API Token to User-Controlled Hostghsa
- highGHSA-qrx8-25qr-5r7v: n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessionsghsa
- highGHSA-2j5h-858j-5mpf: n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpointsghsa
- highGHSA-pmqw-72cg-wx85: n8n: Credential Exfiltration via Permission Bypassghsa
- mediumGHSA-jqpw-qww5-cj4c: n8n: Denial of Service via ZIP decompression in webhook workflowghsa
- highGHSA-42h7-m79w-wvg5: n8n: Stored XSS in Chat Trigger Nodeghsa
- mediumGHSA-h86q-fx34-gfjr: n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verificati…ghsa
- highGHSA-x6p3-m6h9-fx7r: n8n: Microsoft SQL Node Prototype Pollutionghsa
- mediumGHSA-9c38-2mcm-q7f7: n8n: Merge Node SQL Mode Prototype Pollutionghsa
- mediumGHSA-2vff-hj5x-8gq7: n8n: Prototype Pollution enables confused-deputy execution via public webhooksghsa
- highGHSA-v733-mwr6-fgcm: n8n: Same-Origin XSS in Respond to Webhook Nodeghsa
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21