A critical security vulnerability, tracked as CVE-2026-21858 and dubbed "Ni8mare," has been discovered in the open-source workflow automation platform n8n. This flaw allows unauthenticated remote attackers to gain full control over vulnerable n8n instances by exploiting a content-type confusion issue in the platform's workflow processing. The vulnerability, rated CVSS 10.0, enables attackers to access files on the underlying server, potentially exposing sensitive information and allowing further compromise depending on the deployment and workflow configuration. Researchers at Cyera identified and reported the issue, and n8n has issued advisories urging immediate patching.
The Ni8mare vulnerability is distinct from other recent critical flaws in n8n, as it does not require any credentials for exploitation. Over 100,000 n8n servers are believed to be at risk, with the platform widely used for automating tasks and integrating AI services. Administrators are strongly advised to update to the latest secure version and review workflow configurations to mitigate the risk of unauthorized access and system compromise. The disclosure follows a series of high-severity vulnerabilities in n8n, underscoring the urgent need for robust security practices in workflow automation environments.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported attacks targeting CVE-2026-21858 in February 2026 and said it first observed exploitation attempts on 2026-02-04. The activity included a POST request to /form/avatar attempting to read /proc/self/environ via the filepath parameter, indicating public PoC-driven scanning or exploitation.
The Canadian Centre for Cyber Security issued Alert AL26-001 covering CVE-2026-21858 and other n8n flaws. The alert warned that public proof-of-concept exploits existed and advised organizations to patch or restrict public webhook and form endpoints.
Follow-up exposure tracking found 105,753 exposed n8n instances over the weekend, with 59,558 still exposed on Sunday. The update highlighted continued large-scale internet exposure of unpatched deployments after public disclosure.
Horizon3.ai published an analysis arguing that real-world exploitation usually requires uncommon, non-default conditions such as a publicly accessible form workflow and a way to retrieve local files. The company said it found no impacted customer production environments during its review, while still recommending patching.
Researchers and internet scanning data published with the disclosure estimated large numbers of exposed n8n instances, ranging from 26,512 observed internet-facing hosts to claims of more than 100,000 potentially vulnerable servers. The largest concentrations were reported in the United States and Europe.
Multiple reports on the public disclosure date explained that attackers could chain arbitrary file read, secret extraction, forged admin session cookies, and workflow-based command execution to fully compromise self-hosted n8n instances. Cyera named the issue "Ni8mare" and rated it critical with a CVSS score of 10.0.
Public disclosure of CVE-2026-21858 began through GitHub and CVE listings, describing unauthenticated file access via improper webhook request handling and recommending upgrades to 1.121.0 or later. Reports also noted that restricting or disabling public webhook and form endpoints could reduce exposure until patching.
n8n fixed CVE-2026-21858 in release 1.121.0. The patch addressed the vulnerable webhook/form handling affecting versions up to and including 1.65.0.
Cyera researchers privately disclosed CVE-2026-21858, later dubbed "Ni8mare," to n8n in early November 2025. The report described an improper webhook request handling issue that could enable unauthenticated file access and further compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
17 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourceschneier.com
Open sourcelevelblue.com
Open sourcecyber.gc.ca
Open sourcegithub.com
Open sourcethehackernews.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.