← Vulnerability feed

Vulnerability record · CVE-2026-21858 · published 8 January 2026

CVE-2026-21858: n8n form workflows allow unauthenticated file access

N8n · N8n

n8n versions from 1.65.0 up to but not including 1.121.0 fail to properly validate input in certain form-based workflows, letting an attacker read files on the underlying server. Because the flaw is reachable without authentication and can expose sensitive data, it is a serious risk for any internet-facing n8n instance running an affected workflow.

10.0 CVSS 3.1 Critical EPSS 78% · top 0.4% CWE-20 · Improper input validation
10.0CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with no authentication or interaction required and very high EPSS, so exploitation is both easy and likely.

What it is

n8n versions from 1.65.0 up to but not including 1.121.0 fail to properly validate input in certain form-based workflows, letting an attacker read files on the underlying server. Because the flaw is reachable without authentication and can expose sensitive data, it is a serious risk for any internet-facing n8n instance running an affected workflow.

Impact

An unauthenticated remote attacker can read arbitrary files on the host, exposing credentials, configuration and other sensitive data, and may achieve further compromise depending on the deployment and workflows in use.

Attack surface

Reached over the network through a vulnerable form-based workflow; the CVSS vector shows no privileges or user interaction required, so any exposed instance with such a workflow is directly attackable.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.78447, 99.56th percentile) and a third-party advisory is tagged as an exploit, indicating public exploit activity is likely.

What to do

  • Upgrade n8n to version 1.121.0 or later immediately.
  • If patching is delayed, disable or restrict form-based workflows and remove unauthenticated access to the n8n instance.
  • Place n8n behind authentication and network controls so it is not directly reachable from the internet.
  • Rotate any credentials or secrets stored on or accessible from the n8n host after exposure is suspected.
  • Monitor vendor advisory GHSA-v4pr-fm98-w9pg for updates.

Detection

  • Review n8n logs for anomalous requests to form workflow endpoints, especially file-path-like parameters.
  • Alert on unexpected reads of sensitive files (e.g., /etc/passwd, .env, config files) by the n8n process.
  • Audit exposed n8n instances for form-based workflows and unauthenticated reachability.
  • Correlate outbound connections or file access from the n8n host with unusual workflow executions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21858 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-68613n8n workflow expression evaluation RCE for authenticated usersn8n versions from 0.211.0 before 1.120.4, 1.121.1, and 1.122.0 evaluate user-supplied workflow expressions in an execution context that is not suffic…KEVEPSS 99%analysed9.9CVE-2026-1470N8n vulnerabilityn8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated…EPSS 21%9.9CVE-2026-0863N8n code injection vulnerabilityUsing string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted…EPSS 9.4%9.9CVE-2026-21877N8n code injection vulnerabilityn8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us…EPSS 5.4%9.9CVE-2025-68668N8n vulnerabilityn8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node…EPSS 13%9.5CVE-2026-27493N8n code injection vulnerabilityn8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability …EPSS 1.6%9.4CVE-2026-44789N8n prototype pollution vulnerabilityn8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify …EPSS 0.53%9.4CVE-2026-44790N8n argument injection vulnerabilityn8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify …EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2026-21858), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.