NCSC-2026-0248 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platform
n8n has fixed multiple vulnerabilities in the n8n workflow automation platform, specifically in versions 2.10.1, 2.9.3, 1.123.22, and other related releases. The vulnerabilities affect various components within n8n, including the Form nodes, Python Code node, JavaScript Task Runner sandbox, Merge node, Read/Write Files from Disk node, workflow expression evaluation, core workflow editing functionality, GitHub Webhook Trigger node, ZendeskTrigger node, Guardrail node, and Chat Trigger node. - Unauthenticated and authenticated users can, under certain conditions, inject and execute arbitrary code, sometimes via sandbox escapes, leading to remote code execution on the host system. - Vulnerabilities in nodes such as Merge node and Read/Write Files from Disk node allow authenticated users with workflow editing rights to write files and execute shell commands. - Webhook nodes (GitHub and ZendeskTrigger) lack HMAC-SHA256 signature verification, allowing unauthorized POST requests to be sent that trigger workflows. - Authentication bypass vulnerabilities in SSO and Chat Trigger nodes enable the circumvention of security mechanisms and unauthorized access. - Input validation in the Guardrail node can be bypassed, potentially compromising the integrity of workflows. These vulnerabilities are present in multiple versions and releases of n8n and are related to workflow creation, modification, and execution, where exploitation can lead to taking over the host system, manipulating workflows, and bypassing authentication controls.
CSIRTS triage
- What
- Multiple vulnerabilities allow code injection and execution, potentially leading to remote code execution.
- Who is affected
- Users of n8n workflow automation platform with various roles.
- Urgency
- Remediation is necessary due to the potential for remote code execution.
- Action
- Users should update to the latest version of n8n.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n workflow automation platform
Get an email when a new n8n workflow automation platform advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0248
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-274931.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all scored CVEs.
- Low exploitation riskCVE-2026-274940.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-274950.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all scored CVEs.
- Low exploitation riskCVE-2026-274970.77% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
- Low exploitation riskCVE-2026-274980.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Moderate exploitation riskCVE-2026-275778.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 95% of all scored CVEs.
- Low exploitation riskCVE-2026-275780.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-563570.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-563500.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-563600.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-27493 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27494 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27495 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27497 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27498 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27577 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27578 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56357 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56350 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56360 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56349 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56353 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] n8n: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-56353: n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User A…nvd
- unknownCVE-2026-56349: n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node tha…nvd
- mediumCVE-2026-56360: n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webho…nvd
- mediumCVE-2026-56350: n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO us…nvd
- mediumGHSA-mqpr-49jj-32rc: n8n: Webhook Forgery on Github Webhook Triggerghsa
Recent advisories for n8n workflow automation
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0228 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platformncsc-nl · 2026-07-13
- mediumCVE-2026-59209: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an…nvd · 2026-07-09
- mediumCVE-2026-59208: n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2…nvd · 2026-07-09
- mediumCVE-2026-59207: n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents …nvd · 2026-07-09
- highCVE-2026-59206: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an…nvd · 2026-07-09
- unknownNCSC-2026-0212 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platformncsc-nl · 2026-06-29
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30