Vulnerability record · CVE-2026-21858 · published 8 January 2026
CVE-2026-21858: n8n form workflows allow unauthenticated file access
N8n · N8n
n8n versions from 1.65.0 up to but not including 1.121.0 fail to properly validate input in certain form-based workflows, letting an attacker read files on the underlying server. Because the flaw is reachable without authentication and can expose sensitive data, it is a serious risk for any internet-facing n8n instance running an affected workflow.
Description
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 10.0 with no authentication or interaction required and very high EPSS, so exploitation is both easy and likely.
What it is
n8n versions from 1.65.0 up to but not including 1.121.0 fail to properly validate input in certain form-based workflows, letting an attacker read files on the underlying server. Because the flaw is reachable without authentication and can expose sensitive data, it is a serious risk for any internet-facing n8n instance running an affected workflow.
Impact
An unauthenticated remote attacker can read arbitrary files on the host, exposing credentials, configuration and other sensitive data, and may achieve further compromise depending on the deployment and workflows in use.
Attack surface
Reached over the network through a vulnerable form-based workflow; the CVSS vector shows no privileges or user interaction required, so any exposed instance with such a workflow is directly attackable.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.78447, 99.56th percentile) and a third-party advisory is tagged as an exploit, indicating public exploit activity is likely.
What to do
- Upgrade n8n to version 1.121.0 or later immediately.
- If patching is delayed, disable or restrict form-based workflows and remove unauthenticated access to the n8n instance.
- Place n8n behind authentication and network controls so it is not directly reachable from the internet.
- Rotate any credentials or secrets stored on or accessible from the n8n host after exposure is suspected.
- Monitor vendor advisory GHSA-v4pr-fm98-w9pg for updates.
Detection
- Review n8n logs for anomalous requests to form workflow endpoints, especially file-path-like parameters.
- Alert on unexpected reads of sensitive files (e.g., /etc/passwd, .env, config files) by the n8n process.
- Audit exposed n8n instances for form-based workflows and unauthenticated reachability.
- Correlate outbound connections or file access from the n8n host with unusual workflow executions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg | Vendor Advisory |
| https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858 | ExploitThird Party Advisory |
Track CVE-2026-21858 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-21858), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.