CVE-2026-21858: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-21858, dubbed "Ni8mare", is a critical unauthenticated file access and remote code execution vulnerability in the n8n workflow automation platform. It stems from improper input validation in webhook request handling, allowing unauthenticated remote attackers to access arbitrary files on the underlying server by executing certain form-based workflows. Affected versions span n8n 1.65.0 through 1.120.x (Node.js package); version 1.121.0 contains the fix. The vulnerability was published on January 7, 2026, and carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation) in n8n's webhook request handling logic. When processing form-based workflow submissions, n8n fails to properly validate or sanitize input, allowing an attacker to craft malicious requests that cause the server to read and return arbitrary files from the filesystem. Because the vulnerable webhook and form endpoints are publicly accessible by design (to support unauthenticated form submissions), no credentials or prior access are required. The vulnerability was discovered by researcher dorattias and reported to n8n. Multiple public proof-of-concept exploits have been released, including a Python exploit script by Chocapikk and a Metasploit auxiliary module (MSF:AUXILIARY-GATHER-NI8MARE_CVE_2026_21858) (GitHub Advisory, Cyera Research, Rapid7 Blog).

Impact

Successful exploitation allows an unauthenticated remote attacker to read arbitrary files from the n8n server, exposing sensitive data such as credentials, API keys, environment variables, configuration files, and workflow secrets stored on the system. The CVSS scope is "Changed," reflecting that the impact extends beyond the n8n application itself to the underlying host and potentially connected systems. Depending on deployment configuration, this file access can enable further compromise — including lateral movement within the infrastructure — and has been observed enabling full server takeover in real-world attacks. Over 59,000–100,000 internet-exposed n8n instances were identified as potentially vulnerable (BleepingComputer, Cyera Research).

Exploitability

CVE-2026-21858 has been actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Multiple public PoC exploits are available on GitHub (e.g., by Chocapikk, eduardorossi84, Ashwesker, zeroc00I, SystemVll, and others), and a Metasploit auxiliary module has been merged into the framework (Rapid7 Metasploit Wrap-up). Nuclei templates for automated scanning were also published. The threat actor MuddyWater has been attributed to exploitation of this vulnerability per threat intelligence sources. The Zerobot botnet has also been reported exploiting related n8n vulnerabilities. The EPSS score is approximately 5.9% (91st percentile) per the GitHub Advisory, with Feedly reporting an EPSS of ~0.03 at initial publication. Active scanning by French Kubernetes clusters targeting n8n webhook endpoints was observed by GreyNoise (GreyNoise, VulnCheck, The Register).

Exploitation steps

  1. Reconnaissance: Use Shodan, Censys, or FOFA to identify internet-exposed n8n instances running versions 1.65.0–1.120.x. Look for the n8n web interface (default port 5678) or publicly accessible webhook/form endpoints.
  2. Identify vulnerable webhook endpoints: Enumerate publicly accessible form-based workflow endpoints on the target n8n instance. These endpoints do not require authentication by design.
  3. Craft malicious request: Send a specially crafted HTTP request to a vulnerable form-based workflow endpoint. The request exploits improper input validation in the webhook handler to inject a file path or payload that causes the server to process and return arbitrary file contents.
  4. Exfiltrate sensitive files: Target high-value files such as /etc/passwd, .env files containing API keys and database credentials, n8n configuration files (e.g., ~/.n8n/config), or workflow definitions containing embedded secrets.
  5. Escalate access: Use harvested credentials or API keys to authenticate to n8n or connected services, pivot to other systems, or deploy additional payloads for persistent access or lateral movement.
  6. Automate at scale: Use publicly available tools such as the Chocapikk Python exploit (exploit.py), the Metasploit auxiliary module, or Nuclei templates to scan and exploit multiple vulnerable instances in bulk (Cyera Research, GitHub PoC).

Indicators of compromise

  • Network: Unusual HTTP POST or GET requests to n8n webhook/form endpoints (e.g., /webhook/, /form/) from unknown or scanning IP addresses; outbound connections from the n8n server to unexpected external hosts; scanning activity from IP ranges associated with Kubernetes clusters or known threat actors.
  • Logs: n8n access logs showing repeated requests to form-based workflow endpoints with anomalous parameters or path traversal sequences; HTTP 200 responses to unauthenticated requests that should not return file content; error logs indicating file read operations outside expected directories.
  • File System: Unexpected new files or scripts in the n8n installation or data directory; modified .env or configuration files; evidence of credential files being accessed (e.g., access timestamps on /etc/passwd, ~/.n8n/config, or .env).
  • Process: Unusual child processes spawned by the n8n Node.js process (e.g., bash, curl, wget, python); unexpected network connections initiated by the n8n process.
  • Threat Intelligence: IP addresses associated with Zerobot botnet or MuddyWater infrastructure communicating with n8n instances; indicators from GreyNoise and Shadowserver scanning reports for n8n webhook endpoints (GreyNoise, Shadowserver).

Mitigation and workarounds

Patch: Upgrade n8n to version 1.121.0 or later immediately. This is the only official fix (n8n Security Advisory).

Temporary workarounds (if immediate patching is not possible):

  • Restrict or disable publicly accessible webhook and form endpoints.
  • Place n8n behind a firewall or VPN and limit access to trusted IP ranges only.
  • Audit server logs for signs of exploitation or unauthorized file access attempts.

Additional hardening:

  • Review all deployed workflows for publicly exposed form triggers.
  • Rotate any credentials, API keys, or secrets that may have been stored in environment variables or configuration files accessible to the n8n process.
  • Monitor for indicators of compromise using Nuclei templates and GreyNoise/Shadowserver feeds.

Community reactions

The vulnerability received extensive coverage across the security community immediately after disclosure on January 7, 2026. The Hacker News, BleepingComputer, The Register, CyberScoop, CSO Online, and Security Affairs all published detailed articles within hours of disclosure (BleepingComputer, The Register). Security researcher Bruce Schneier noted the vulnerability on his blog. Rapid7, Horizon3.ai, Cyera, Arctic Wolf, Field Effect, SOCRadar, Picus Security, LevelBlue/SpiderLabs, Aikido, Orca Security, and SonicWall all published technical analyses. Government agencies including CISA, Canadian Centre for Cyber Security (CCCS), Singapore CSA, Belgian CCB, and Australian ACSC issued advisories. The n8n community forum saw active discussion, with users urging immediate updates. VulnCheck published research highlighting a gap in CISA KEV coverage for n8n-related vulnerabilities (VulnCheck). The vulnerability also attracted attention on Reddit (r/netsec, r/cybersecurity, r/n8n) and Hacker News, with significant community engagement.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103493HIGH8.1
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103494MEDIUM6.6
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103495MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management