[UPDATE] [high] n8n: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, perform SQL injection and cross-site scripting attacks, manipulate data, cause a Denial of Service condition, or disclose sensitive information, which may allow further attacks including privilege escalation.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, perform SQL injection and cross-site scripting attacks, manipulate data, cause a Denial of Service condition, or disclose sensitive information.
- Who is affected
- Remote attackers exploiting vulnerabilities in n8n.
- Urgency
- Remediation is urgent due to the high severity and potential for significant impact.
- Action
- Update to the latest version of n8n to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1875
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-543030.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-567770.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-567780.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-567760.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-567750.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543010.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543020.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543040.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543050.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543060.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-56778: n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API …nvd
- highCVE-2026-56776: n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflow…nvd
- mediumCVE-2026-56775: n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutat…nvd
- mediumCVE-2026-56777: n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security val…nvd
- unknownNCSC-2026-0212 [1.00] [M/H] Vulnerabilities fixed in n8n workflow automation platformncsc-nl
- highGHSA-rm2v-h48j-895m: n8n: SecurityScorecard Node Leaks API Token to User-Controlled Hostghsa
- highGHSA-qrx8-25qr-5r7v: n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessionsghsa
- highGHSA-2j5h-858j-5mpf: n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpointsghsa
- highGHSA-pmqw-72cg-wx85: n8n: Credential Exfiltration via Permission Bypassghsa
- mediumGHSA-jqpw-qww5-cj4c: n8n: Denial of Service via ZIP decompression in webhook workflowghsa
- highGHSA-42h7-m79w-wvg5: n8n: Stored XSS in Chat Trigger Nodeghsa
- mediumGHSA-h86q-fx34-gfjr: n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verificati…ghsa
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25