CVE-2026-27493
CVSS 9 CRITICAL: n8n is an open source workflow automation platform. EPSS 2% (74º percentile).
Vulnerabilità · 201 giorni fa
Due vulnerabilità critiche in n8n consentono l'esecuzione remota di comandi (RCE) e l'evasione della sandbox. Gli errori sono identificati come CVE-2026-27493 e CVE-2026-27577 e colpiscono istanze cloud e self-hosted. Un exploit può permettere l'estrazione di tutte le credenziali memorizzate nel database di n8n, esponendo sistemi collegati.
CVSS 9 CRITICAL: n8n is an open source workflow automation platform. EPSS 2% (74º percentile).
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 1% (62º percentile).
3 fonti che coprono questa storia
Critical Zero-Click Flaw in n8n Allows Full Server Compromise
The critical vulnerability affecting both cloud and self-hosted n8n instances requires no authentication or even n8n account to be exploited
Critical N8n Vulnerabilities Allowed Server Takeover
The bugs allowed unauthenticated attackers to execute arbitrary code, steal credentials, and take over servers.
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Two critical n8n flaws (CVSS 9.4, 9.5) enable RCE via expression sandbox escape and public forms, risking credential exposure.
Part of the PlainSec briefing for 2026-03-13