
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27497 is a Remote Code Execution (RCE) vulnerability in n8n, an open-source workflow automation platform, arising from SQL injection and code injection flaws in the Merge node's SQL query mode. An authenticated user with workflow creation or modification permissions can exploit this to execute arbitrary code and write arbitrary files on the n8n server. It was disclosed on February 25, 2026, and affects all n8n versions before 1.123.22, versions 2.0.0 through 2.9.2, and version 2.10.0. The vulnerability carries a CVSS v4.0 base score of 9.4 (Critical) and a CVSS v3.1 score of 8.8 (High) (Github Advisory, n8n Advisory).
The root cause is a combination of CWE-89 (SQL Injection) and CWE-94 (Code Injection) — the Merge node's SQL query mode fails to properly neutralize user-supplied input before incorporating it into SQL commands and code execution contexts. An authenticated attacker can craft a malicious workflow leveraging the Merge node's SQL query mode to inject arbitrary SQL or code payloads that are evaluated server-side, resulting in arbitrary command execution and file writes on the host. No special configuration is required beyond having workflow creation or editing permissions, and no user interaction is needed beyond the attacker's own actions. The vulnerability was reported by security researchers allsmog and nil340 (Github Advisory, n8n Advisory).
Successful exploitation allows an authenticated attacker to achieve full server compromise — executing arbitrary code, reading and writing arbitrary files, and potentially exfiltrating sensitive data including stored credentials and workflow secrets. The CVSS v4.0 scoring reflects high impact across both the vulnerable system and subsequent systems (confidentiality, integrity, and availability all rated High), indicating significant potential for lateral movement to other infrastructure reachable from the n8n server. Attackers could also establish persistent access by writing web shells or backdoors, modify or destroy workflows and data, and disrupt platform availability (Github Advisory, Feedly).
As of the disclosure date, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.076% (23rd percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and the requirement for only low-privilege authenticated access make it highly exploitable once an attacker gains any foothold on the platform, and the vulnerability has attracted attention from multiple national CERTs including Belgium's CCB and Ireland's NCSC (CCB Advisory, NCSC Ireland).
sh, bash, curl, wget, python, nc) that are not part of normal n8n operation; outbound network connections initiated by the n8n process to unknown external IPs.n8n has released patched versions on February 25, 2026: 1.123.22, 2.9.3, and 2.10.1 — users should upgrade to one of these versions or later immediately (Github Advisory, n8n Release 1.123.22, n8n Release 2.10.1). If immediate patching is not possible, two temporary mitigations are available: (1) restrict workflow creation and editing permissions to fully trusted users only, and (2) disable the Merge node entirely by adding n8n-nodes-base.merge to the NODES_EXCLUDE environment variable. These workarounds do not fully eliminate the risk and should only be used as short-term measures while preparing to upgrade (n8n Advisory).
n8n published a security blog post and community forum bulletin on February 25, 2026, disclosing the vulnerability and directing users to patch immediately (n8n Blog, n8n Community). Multiple national cybersecurity agencies responded promptly: Belgium's Centre for Cybersecurity (CCB) issued a warning urging immediate patching, and Ireland's NCSC published a dedicated advisory (CCB Advisory, NCSC Ireland). Security media including The Hacker News and Heise covered the vulnerability, with The Hacker News noting it as part of a broader set of critical n8n flaws allowing RCE and credential exposure (The Hacker News, Heise). SecurityOnline described the vulnerability cluster as "triple 9.4 severity RCE flaws" threatening n8n workflow servers.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."