Vulnerabilities & Exploits · Web App Attack
Critical n8n Flaws Enable Server Takeover and Credential Theft Two critical vulnerabilities in the n8n workflow platform allow unauthenticated attackers to run commands and escape the sandbox. Both cloud and self-hosted instances are affected, and attackers could extract all credentials stored in n8n’s database, exposing connected systems.
3 sources · Mar 12
CVE-2026-27577 NVD KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 10% (95th percentile).
CVE-2026-27493 NVD KEV
CVSS 9 CRITICAL: n8n is an open source workflow automation platform. EPSS 1% (67th percentile).
Timeline Sources Mar 12 Infosecurity Magazine
Critical Zero-Click Flaw in n8n Allows Full Server Compromise
The critical vulnerability affecting both cloud and self-hosted n8n instances requires no authentication or even n8n account to be exploited
original Mar 12 SecurityWeek
Critical N8n Vulnerabilities Allowed Server Takeover
The bugs allowed unauthenticated attackers to execute arbitrary code, steal credentials, and take over servers.
original Mar 11 The Hacker News
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Two critical n8n flaws (CVSS 9.4, 9.5) enable RCE via expression sandbox escape and public forms, risking credential exposure.
original Part of the PlainSec briefing for 2026-03-13
Every edition of this story: Critical n8n Flaws Enable Server Takeover and Credential Theft
More from today
Vulnerabilities & Exploits · Web App Attack
Critical n8n Flaws Enable Server Takeover and Credential Theft Two critical vulnerabilities in the n8n workflow platform allow unauthenticated attackers to run commands and escape the sandbox. Both cloud and self-hosted instances are affected, and attackers could extract all credentials stored in n8n’s database, exposing connected systems.
3 sources · Mar 12
CVE-2026-27577 NVD KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 10% (95th percentile).
CVE-2026-27493 NVD KEV
CVSS 9 CRITICAL: n8n is an open source workflow automation platform. EPSS 1% (67th percentile).
Timeline Sources Mar 12 Infosecurity Magazine
Critical Zero-Click Flaw in n8n Allows Full Server Compromise
The critical vulnerability affecting both cloud and self-hosted n8n instances requires no authentication or even n8n account to be exploited
original Mar 12 SecurityWeek
Critical N8n Vulnerabilities Allowed Server Takeover
The bugs allowed unauthenticated attackers to execute arbitrary code, steal credentials, and take over servers.
original Mar 11 The Hacker News
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Two critical n8n flaws (CVSS 9.4, 9.5) enable RCE via expression sandbox escape and public forms, risking credential exposure.
original Part of the PlainSec briefing for 2026-03-13
Every edition of this story: Critical n8n Flaws Enable Server Takeover and Credential Theft
More from today