[UPDATE] [high] n8n: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in n8n to gain elevated privileges, including administrator rights, execute arbitrary code, manipulate data, bypass security measures, disclose confidential information, or conduct cross-site and man-in-the-middle attacks.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in n8n to gain elevated privileges, including administrator rights, execute arbitrary code, manipulate data, bypass security measures, disclose confidential information, or conduct cross-site and man-in-the-middle attacks.
- Who is affected
- Users of n8n in affected versions.
- Urgency
- Remediation is urgent due to the high severity and potential impact of the vulnerabilities.
- Action
- Update to the latest version of n8n.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0877
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-563560.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-563590.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-274960.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-336600.95% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-336630.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-336650.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-336960.79% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-337200.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-337220.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-337240.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-56356 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56359 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27496 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33660 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33663 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33665 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33696 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33720 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33722 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33724 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33749 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33751 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-56359: n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management fl…nvd
- mediumCVE-2026-56356: n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS…nvd
- highGHSA-c545-x2rh-82fc: n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeoverghsa
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25