INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution

| 2026-01-28 12:43 CRITICAL HIGH
Executive Summary AI-generated
The discovery of two critical security flaws in the n8n workflow automation platform has sent shockwaves through the cybersecurity community. The vulnerabilities, identified by JFrog Security Research team as CVE-2026-1470 and CVE-2026-0863, have been listed below: CVE-2026-1470 is an eval injection vulnerability that could allow authenticated users to bypass Expression sandbox mechanism and achieve full remote code execution on n8n's main node. The score for this exploit has been rated as 9.9 by CVSS. The same vulnerabilities also pose a threat with CVE-2026-0863, which allows unauthenticated attackers to bypass the Expression sandbox mechanism and run arbitrary Python code on the underlying operating system. This vulnerability was scored at 8.5 by CVSS. These flaws have been identified in more than 39,000 n8n instances as of January 27, according to data from the Shadowserver Foundation. The vulnerabilities could potentially be exploited by attackers who are not authenticated and can bypass the platform's sandbox restrictions.
Technical Mitigations AI-generated
* Update n8n instances: Users should update their n8n instances to the following versions: * CVE-2026-1470 - 1.123.17, 2.4.5, or 2.5.1 * CVE-2026-0863 - 1.123.14, 2.3.5, or 2.4.2 * Implement additional security measures: Organizations should consider implementing additional security measures to mitigate the risks associated with these vulnerabilities, such as: * Enforcing strict access controls and authentication mechanisms for n8n instances * Implementing sandbox restrictions on Python code execution in n8n instances * Regularly monitoring and updating n8n instances to ensure they remain secure
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation OreOperation Ore CVE-2026-1470CVE-2026-1470 CVE-2026-21858CVE-2026-21858 CVE-2026-0863CVE-2026-0863
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment healthhealth technologytechnology legallegal
Incident Timeline
2025-01-15
N8n's n8n Flaws Allow Authenticated Remote Code Execution.
infrastructure N8N
2026-01-07
Cyera revealed the "Ni8mare" vulnerability (CVE-2026-21858) in a blog post yesterday.
vulnerability CVE-2026-21858
organisation Ni8mare
January 15, 2026
Threat actors exploited two high-severity n8n flaws to allow authenticated remote code execution in a targeted system.
January 15, 2026 11:16 PM
Threat actors exploited two high-severity n8n flaws in the popular database management software to gain unauthorized access and execute authenticated remote code.
January 16, 2026
Threat actors exploited two high-severity n8n flaws allowing them to execute authenticated remote code in the n8n application.
infrastructure N8N
observable node.js
general_metric 2 applications
January 17, 2026
Threat actors exploited two high-severity n8n flaws in a widely used web application to gain authenticated remote code execution.
January 18, 2026
Threat actors exploited two high-severity n8n flaws in the LLM's input processing pipeline to gain authenticated remote code execution.
organisation LLM
January 18, 2026 12:10 PM
Threat actors exploited two high-severity n8n flaws in Microsoft's iAPX system to allow authenticated remote code execution.
organisation Microsoft
January 27, 2026
Threat actors exploited two high-severity n8n flaws in the n8n framework to allow authenticated remote code execution.
infrastructure N8N
organisation the Shadowserver Foundation
general_metric 39,000 n8n instances
Jan 28, 2026
Two high-severity vulnerabilities in n8n allowed authenticated remote code execution.
infrastructure N8N
organisation CVE-2026-0863
organisation JFrog
organisation CVE-2026-1470's
organisation LLM
organisation n8n
organisation IAM
organisation The Hacker News
infrastructure 1.123.17
infrastructure 2.4.5
infrastructure 2.5.1
infrastructure 1.123.14
infrastructure 2.3.5
infrastructure 2.4.2
organisation Cyera Research Labs
organisation Ni8mare
organisation the JFrog Security Research
Jan 28
Threat actors used a high-severity n8n flaw to allow authenticated remote code execution.
infrastructure N8N
tactic Remote Code Execution
organisation Vulnerability / Workflow Automation
2026-01-28
Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution.
organisation US Corporate Interests
organisation US Corporates
organisation Corporate
infrastructure Windows
organisation Operation Ore
organisation Met Operational Units
organisation the “National Crime Agency”(NCA
organisation Met
organisation NCA
organisation npm security
organisation Prompt Engineering
organisation Are Getting Better
organisation Getting Better at Finding and Exploiting Internet
infrastructure N8N
infrastructure 100,000 estimated servers
victims 10,000 employees
organisation CVSS
infrastructure 1.121.0
organisation Node.js
organisation AI Agents
organisation NPM
organisation node
organisation EU
organisation Microsoft
victims 1 customers
organisation Current AI LLM
organisation ML Systems
organisation Microsft
organisation Beguile
organisation System Administrator Privileges
organisation ePos
organisation Credit Card
organisation ICT Professionals
organisation Harvard
organisation Kennedy School
organisation EFF
organisation Inrupt, Inc.
organisation Apple
organisation Bug Bounty Program
organisation Defend Privacy--Support
organisation CI
organisation API
November 9
N8N provided a patch for the high-severity vulnerability.
infrastructure N8N
Tactical Metrics
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​N8N
Affected Product
Metrics
infrastructure
100,000
Estimated Servers
Metrics
infrastructure
​1.121.0
Software Version
Metrics
victims
1
Customers
Metrics
infrastructure
​1.123.17
Software Version
Metrics
infrastructure
​2.4.5
Software Version
Metrics
infrastructure
​2.5.1
Software Version
Metrics
infrastructure
​1.123.14
Software Version
Metrics
infrastructure
​2.3.5
Software Version
Metrics
infrastructure
​2.4.2
Software Version
Metrics
victims
10,000
Employees
Intelligence Sources
Schneier on Security 2026-01-15
New Vulnerability in n8n Schneier on Security
Infosecurity-Magazine 2026-01-08