
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21858, dubbed "Ni8mare", is a critical unauthenticated file access and remote code execution vulnerability in the n8n workflow automation platform. It stems from improper input validation in webhook request handling, allowing unauthenticated remote attackers to access arbitrary files on the underlying server by executing certain form-based workflows. Affected versions span n8n 1.65.0 through 1.120.x (Node.js package); version 1.121.0 contains the fix. The vulnerability was published on January 7, 2026, and carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, n8n Security Advisory).
The root cause is classified as CWE-20 (Improper Input Validation) in n8n's webhook request handling logic. When processing form-based workflow submissions, n8n fails to properly validate or sanitize input, allowing an attacker to craft malicious requests that cause the server to read and return arbitrary files from the filesystem. Because the vulnerable webhook and form endpoints are publicly accessible by design (to support unauthenticated form submissions), no credentials or prior access are required. The vulnerability was discovered by researcher dorattias and reported to n8n. Multiple public proof-of-concept exploits have been released, including a Python exploit script by Chocapikk and a Metasploit auxiliary module (MSF:AUXILIARY-GATHER-NI8MARE_CVE_2026_21858) (GitHub Advisory, Cyera Research, Rapid7 Blog).
Successful exploitation allows an unauthenticated remote attacker to read arbitrary files from the n8n server, exposing sensitive data such as credentials, API keys, environment variables, configuration files, and workflow secrets stored on the system. The CVSS scope is "Changed," reflecting that the impact extends beyond the n8n application itself to the underlying host and potentially connected systems. Depending on deployment configuration, this file access can enable further compromise — including lateral movement within the infrastructure — and has been observed enabling full server takeover in real-world attacks. Over 59,000–100,000 internet-exposed n8n instances were identified as potentially vulnerable (BleepingComputer, Cyera Research).
CVE-2026-21858 has been actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Multiple public PoC exploits are available on GitHub (e.g., by Chocapikk, eduardorossi84, Ashwesker, zeroc00I, SystemVll, and others), and a Metasploit auxiliary module has been merged into the framework (Rapid7 Metasploit Wrap-up). Nuclei templates for automated scanning were also published. The threat actor MuddyWater has been attributed to exploitation of this vulnerability per threat intelligence sources. The Zerobot botnet has also been reported exploiting related n8n vulnerabilities. The EPSS score is approximately 5.9% (91st percentile) per the GitHub Advisory, with Feedly reporting an EPSS of ~0.03 at initial publication. Active scanning by French Kubernetes clusters targeting n8n webhook endpoints was observed by GreyNoise (GreyNoise, VulnCheck, The Register).
/etc/passwd, .env files containing API keys and database credentials, n8n configuration files (e.g., ~/.n8n/config), or workflow definitions containing embedded secrets.exploit.py), the Metasploit auxiliary module, or Nuclei templates to scan and exploit multiple vulnerable instances in bulk (Cyera Research, GitHub PoC)./webhook/, /form/) from unknown or scanning IP addresses; outbound connections from the n8n server to unexpected external hosts; scanning activity from IP ranges associated with Kubernetes clusters or known threat actors..env or configuration files; evidence of credential files being accessed (e.g., access timestamps on /etc/passwd, ~/.n8n/config, or .env).bash, curl, wget, python); unexpected network connections initiated by the n8n process.Patch: Upgrade n8n to version 1.121.0 or later immediately. This is the only official fix (n8n Security Advisory).
Temporary workarounds (if immediate patching is not possible):
Additional hardening:
The vulnerability received extensive coverage across the security community immediately after disclosure on January 7, 2026. The Hacker News, BleepingComputer, The Register, CyberScoop, CSO Online, and Security Affairs all published detailed articles within hours of disclosure (BleepingComputer, The Register). Security researcher Bruce Schneier noted the vulnerability on his blog. Rapid7, Horizon3.ai, Cyera, Arctic Wolf, Field Effect, SOCRadar, Picus Security, LevelBlue/SpiderLabs, Aikido, Orca Security, and SonicWall all published technical analyses. Government agencies including CISA, Canadian Centre for Cyber Security (CCCS), Singapore CSA, Belgian CCB, and Australian ACSC issued advisories. The n8n community forum saw active discussion, with users urging immediate updates. VulnCheck published research highlighting a gap in CISA KEV coverage for n8n-related vulnerabilities (VulnCheck). The vulnerability also attracted attention on Reddit (r/netsec, r/cybersecurity, r/n8n) and Hacker News, with significant community engagement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."