[NEW] [high] n8n: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, conduct cross site scripting or server side request forgery, or trigger a denial of service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow arbitrary code execution, security bypass, information disclosure, data manipulation, cross-site scripting, server-side request forgery, and denial of service.
- Who is affected
- All n8n deployments.
- Urgency
- High severity with code execution capability requires urgent patching.
- Action
- Apply available n8n security patches immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2681
Recent advisories for n8n
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-86996: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow s…nvd · 2026-09-08
- unknownCVE-2026-86995: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the…nvd · 2026-09-08
- unknownCVE-2026-86994: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the…nvd · 2026-09-08
- unknownCVE-2026-86993: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a L…nvd · 2026-09-08
- unknownCVE-2026-86085: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/role…nvd · 2026-09-08
- unknownCVE-2026-86084: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the…nvd · 2026-09-08
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Red Hat Enterprise Linux (libreswan): Mehrere Schwachstellen ermöglichen Denial of Service2026-09-08
- medium[UPDATE] [mittel] Red Hat Enterprise Linux (sg3_utils): Schwachstelle ermöglicht Ausführen von beliebigem Prog…2026-09-08
- medium[UPDATE] [mittel] Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen2026-09-08
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-08
- high[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen2026-09-08