A critical CVSS 10.0 vulnerability in locally deployed n8n automation instances, tracked as CVE-2026-21858 and dubbed Ni8mare, enables unauthenticated attackers to read arbitrary local files, bypass authentication, and execute commands. The flaw stems from Content-Type confusion in webhook parsing: the Form Webhook node can invoke file handling without requiring multipart/form-data, allowing attacker-controlled file paths to be copied into persistent storage. Researchers estimate that roughly 100,000 internet-exposed servers may be affected.
Attackers can use the file-read primitive to obtain sensitive files, including /etc/passwd, the local SQLite database, and n8n configuration secrets. With database contents and the instance secret, they can forge an n8n-auth session cookie, gain administrator access, and create workflows using the Execute Command node for remote code execution. Organizations running self-hosted n8n should upgrade to version 1.121.0 or later; no official workaround is available.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
n8n assigned CVE-2026-21858 to the critical Content-Type confusion flaw, which can enable arbitrary local-file reads, authentication bypass, and code execution on locally deployed instances.
n8n published a patched version addressing the reported unauthenticated file-access vulnerability.
n8n acknowledged receipt of Cyera Research Labs' vulnerability report.
Cyera Research Labs reported the critical n8n file-access vulnerability to n8n through responsible disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.