Vulnerabilities · 187 days ago

Critical n8n Flaws Enable Server Takeover and Credential Theft

Two critical vulnerabilities in the n8n workflow platform allow unauthenticated attackers to run commands and escape the sandbox. Both cloud and self-hosted instances are affected, and attackers could extract all credentials stored in n8n’s database, exposing connected systems.

CVE-2026-27577

NVD KEV

CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 10% (95th percentile).

CVE-2026-27493

NVD KEV

CVSS 9 CRITICAL: n8n is an open source workflow automation platform. EPSS 1% (67th percentile).

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-13

Editions

Related stories