
CVE-2026-21858

A critical unauthenticated remote code execution vulnerability in an open-source workflow automation platform.
CVE-2026-21858, nicknamed “Ni8mare,” is a critical vulnerability discovered in n8n — a popular platform for building automation workflows (e.g., automating API calls, integrations, SaaS connectors).
It allows unauthenticated remote attackers to interact with improperly validated webhook/form endpoints and gain unauthorized access to files and internal server resources.
A successful exploit can lead to full remote code execution (RCE) and complete instance takeover.
This represents the maximum possible severity for a remote code execution flaw.
The vulnerability impacts the open-source n8n platform:
= 1.65.0 and < 1.121.0
id="vsurvey1"
All self-hosted instances running versions prior to 1.121.0 are vulnerable.
An attacker exploiting this vulnerability can:
Instances exposed on the public internet are particularly at risk.
This vulnerability is:
Evidence from internet scanning suggests tens of thousands of potentially exposed instances remain reachable online.
Watch for:
Update n8n to version 1.121.0 or later — this release includes the fix for CVE-2026-21858.
While updating, reduce exposure:
If you run n8n **anywhere — especially self-hosted, internet-facing instances — patch **to version 1.121.0 or higher immediately. The risk of full system compromise is high, and automated exploits are possible given the public details of this issue.
| Metric | Details |
|---|
| CVSS Score (v3.1) | 10.0 — Critical |
| Attack Vector | Network |
| Privileges Required | None |
| Authentication Required | ❌ None |
| User Interaction | ❌ None |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | None |
| Field | Value |
|---|
| CVE ID | CVE-2026-21858 |
| Nickname | Ni8mare |
| Product | n8n Workflow Automation |
| Severity | Critical (CVSS 10.0) |
| Type | Unauthenticated Remote Code Execution |
| Auth Required | No |
| Fixed Version | ≥ 1.121.0 |