Skip to main content
QUIETLYTIC
Vulnerability

10 n8n CVEs (CVE-2026-86075)

Ten further n8n CVEs: unauthenticated storage exhaustion, credential-exfiltration paths, a webhook signature bypass, and a KEV-listed flaw.

CVE-2026-86075
Threat Level
HIGH
CVSS
7.5
Status
Active Exploitation
Confidence
Medium
Affected Products
n8n

Full CVE Roster

All 10 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 1 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2026-86075 — 7.5 high
CVE-2026-86082 — 6.5 medium
CVE-2026-86079 — 6.5 medium
CVE-2026-86078 — 6.5 medium
CVE-2026-86084 — 5.5 medium
CVE-2026-86080 — 5.3 medium
CVE-2026-86995 — 4.3 medium
CVE-2026-21858 — — — Yes
CVE-2026-86074 — — —
CVE-2026-86081 — — —

The remaining ten CVEs in n8n’s September 2026 disclosure batch don’t share one root cause the way the expression-engine and access-control clusters do — they span an unauthenticated storage-exhaustion bug, two credential-exfiltration paths, a webhook signature bypass, a regex denial-of-service, a local-repository-read bypass, and a KEV-listed flaw our ledger has almost no detail on. What ties them together is that each is a real, independently fixable defect in a specific n8n node or subsystem, not a variation on the same theme — so we’re reporting them as a single roundup by disclosure batch rather than forcing a thematic frame that doesn’t fit.

CVE-2026-86075: unauthenticated storage exhaustion via OAuth dynamic client registration

Per the GitHub Advisory Database record, n8n’s OAuth Dynamic Client Registration endpoint validated the size of the redirect_uris field but left client_name and grant_types checked only for presence, not bounded length. An unauthenticated caller could repeatedly submit oversized values for those fields, persisted to the database without limit. CWE-770 (Allocation of Resources Without Limits). CVSS base 7.5 (high; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Impact: an unauthenticated remote party could exhaust database storage over time, degrading instance availability. Fixed in 2.37.7 and 2.38.2. Confidence: medium.

CVE-2026-86082: domain-restriction bypass exfiltrates OpenAI credentials via model-search endpoint

Per the GitHub Advisory Database record, the OpenAI Chat Model node enforces an administrator-configured allowed-domain restriction on its credential for normal API calls, but the model-search/listing code path omitted the corresponding check. A workflow editor could set a custom base URL on that path and have the credential sent to a host of their choosing. CWE-918 (SSRF). CVSS base 6.5 (medium; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Impact: a workflow editor could exfiltrate a domain-restricted OpenAI credential to an arbitrary host, circumventing an administrator’s configured restriction. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

CVE-2026-86079: path injection in Elasticsearch nodes via unencoded identifiers

Per the GitHub Advisory Database record, the Elasticsearch and ElasticSecurity nodes built REST request paths by interpolating workflow-controlled index and document identifiers directly into the URL without encoding them as a single path segment. An identifier containing path separators could change which endpoint the request actually reached. CWE-22 (Path Traversal). CVSS base 6.5 (medium; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Impact: a workflow operation intended to touch one document or index could instead reach a different index or a cluster-administration endpoint, using the credential stored for that node. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

CVE-2026-86078: prototype pollution via workflow structure summary leads to denial of service

Per the GitHub Advisory Database record, an Instance AI workflow-summary function used node names and connection keys taken from a stored workflow as plain object keys without validation. Because the editor’s client-side restriction on reserved names could be bypassed by submitting a workflow directly through the REST API, a reserved property name resolved onto the shared object prototype instead of creating an own property. CWE-1321 (Prototype Pollution). CVSS base 6.5 (medium; vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Impact: a crafted node or connection name could pollute Object.prototype in the main n8n process, disrupting handling of subsequent, unrelated requests on the instance. Fixed in 2.37.7 and 2.38.2. Confidence: medium.

CVE-2026-86084: disabled OIDC SSO endpoints remain active and issue valid sessions

Per the GitHub Advisory Database record, n8n’s public OIDC login and callback endpoints didn’t check whether OIDC was still the instance’s actively enabled authentication method before completing the login flow. An Enterprise administrator who had configured and later disabled an identity provider still had a functioning login route. CWE-288 (Authentication Bypass Using an Alternate Path). CVSS base 5.5 (medium; vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N). Impact: a previously configured OIDC identity provider an administrator believed was disabled could still be used to obtain a valid, authenticated session. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

CVE-2026-86080: GitHub Trigger 422-reuse path skips webhook secret storage, signature verification fails open

Per the GitHub Advisory Database record, when the GitHub Trigger node registers a webhook, it generates a signing secret to verify incoming deliveries. If GitHub’s API responded with an HTTP 422 because a webhook already existed for that URL, the node adopted the existing hook’s ID and events but discarded the newly generated secret, leaving the workflow’s stored data with a webhook ID but no signing secret. CWE-347 (Improper Verification of Cryptographic Signature). CVSS base 5.3 (medium; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Impact: deliveries to that workflow’s webhook URL were accepted without valid signature verification, letting anyone who could reach the endpoint trigger the workflow as if they were GitHub. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

CVE-2026-86995: Git node config-key bypass enables local repository read

Per the GitHub Advisory Database record, the Git node validated the repository parameter supplied directly for a fetch or pull operation, but a related function wrote a branch.<name>.remote value into the repository’s local git configuration without the same validation. A later fetch or pull resolved the actual remote from that unvalidated configuration value instead of the checked parameter. CWE-22 (Path Traversal) and CWE-73 (External Control of File Name or Path). CVSS base 4.3 (medium; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Impact: an authenticated user with workflow-edit permission could point the Git node’s fetch/pull at any local repository readable by the n8n process and retrieve its contents, bypassing the intended path restriction. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

CVE-2026-21858: KEV-listed, actively exploited — ledger detail is minimal

Listed in VulnCheck KEV (added 2026-01-09) with an EPSS score of 0.784, indicating meaningful observed or imminent exploitation. Our source data for this CVE contains only a generic weakness-class title (“Improper Input Validation”) with no description, no CVSS score, and no affected-component detail — we’re reporting the exploitation signal because it’s real and independently sourced from a KEV catalog, but explicitly flagging that we cannot describe the underlying flaw’s mechanism, impact, or fix status beyond what’s stated here, because our ledger doesn’t contain it. Confidence: medium on the exploitation claim (single KEV source); the technical mechanism is UNKNOWN. n8n users should consult n8n’s own advisories directly for this CVE’s technical detail and remediation guidance rather than relying on this summary.

CVE-2026-86074: Instance AI credential setup accepts unvalidated probe URL

Per the GitHub Advisory Database record, n8n’s Instance AI credential setup flow accepted a credential test/verification URL without confirming it matched the origin of the workflow node it was configuring for, letting a URL introduced elsewhere in the setup flow direct authenticated credential-verification requests to an unintended destination. CWE-918 (SSRF). No CVSS score is present in our ledger for this CVE. Impact: third-party API credentials configured through the Instance AI setup flow could have their verification requests, and the associated secrets, directed to an unintended destination. Fixed in 2.37.7 and 2.38.2. Confidence: medium.

CVE-2026-86081: regular expression denial of service via Git node clone path

Per the GitHub Advisory Database record, the default value of n8n’s blocked-file-pattern setting is a regular expression susceptible to catastrophic backtracking, and the Git node’s clone operation evaluates a workflow-controlled destination path against this pattern synchronously in the main n8n process. CWE-1333 (Inefficient Regular Expression Complexity). No CVSS score is present in our ledger for this CVE. Impact: an authenticated user able to edit and run a workflow could freeze the entire n8n instance for all users with a single workflow execution. Fixed in 1.123.76, 2.37.7, and 2.38.2. Confidence: medium.

Confidence and evidence gaps

The seven scored CVEs each carry near-identical NVD and GitHub Advisory Database text in our ledger — the same mirrored-description pattern as the rest of this batch — so we’re holding confidence at medium rather than high throughout. Three entries (CVE-2026-21858, CVE-2026-86074, CVE-2026-86081) have no CVSS score in our ledger at all; we’ve placed them after the scored entries rather than guessing at a severity band. CVE-2026-21858 is the most significant gap in this entire n8n batch: it’s the second confirmed-exploited, KEV-listed n8n CVE we found this round (alongside CVE-2025-68613 in our expression sandbox RCE roundup), yet our ledger carries no technical description for it — a real intelligence gap we’re naming explicitly rather than papering over with invented detail.

Why this matters

This batch reads less like a single vulnerability class and more like the output of a broad security review across n8n’s node library and platform services — OAuth registration, three different node types (Elasticsearch, GitHub, Git), OIDC session handling, and an AI-credential setup flow all turned up distinct issues in the same disclosure wave. The two credential-exfiltration paths (CVE-2026-86082’s domain-restriction bypass, CVE-2026-86074’s unvalidated probe URL) are worth specific attention if your n8n instance stores third-party API keys: both let a workflow-level actor redirect an already-configured credential to a destination the administrator never authorized, which is a materially different risk than a workflow merely misbehaving.

Frequently Asked Questions

Is any CVE in this roundup being actively exploited? Yes — CVE-2026-21858 is listed in VulnCheck KEV with an EPSS score of 0.784, though our ledger has no technical detail on the underlying flaw. None of the other nine CVEs in this roundup carry any KEV listing or exploitation evidence.

Which of these ten is the most severe by CVSS? CVE-2026-86075, CVSS 7.5 — the unauthenticated OAuth dynamic-client-registration storage-exhaustion bug, the only one of the ten scored entries rated high rather than medium.

Do the two credential-exfiltration CVEs (86082, 86074) require special access to exploit? CVE-2026-86082 requires workflow-editor access to set a custom base URL on the affected node. CVE-2026-86074’s record doesn’t specify a required privilege level beyond access to the Instance AI credential setup flow itself.

Which n8n versions fix all ten? Version coverage varies per CVE — see each section above for its specific fixed versions. Most land in the 2.37.7/2.38.2 line, with several also backported to 1.123.76; CVE-2026-21858’s fix status isn’t stated in our ledger.


Data sourced from the National Vulnerability Database (NVD), the GitHub Advisory Database, and VulnCheck KEV, evaluated September 2026. This product uses the NVD API but is not endorsed or certified by the NVD. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 GitHub Advisory Database
03 VulnCheck KEV

Related intelligence


Analyst tools