CVE-2026-21858 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-21858 requires immediate attention.
· 3 min read
```htmlExecutive Summary
A critical vulnerability identified as CVE-2026-21858 has been discovered in the n8n workflow automation tool. This flaw allows unauthorized remote attackers to access sensitive files on the underlying server through specific workflows. Given its critical severity rating (CVSS 10), immediate action is essential for solo developers and small teams using affected versions of n8n.
Immediate Action
- Upgrade to n8n version
1.121.0or later immediately. - Temporarily restrict or disable publicly accessible webhook and form endpoints until the upgrade is complete.
- Review your workflows to identify any that may expose sensitive data.
- Monitor for any unusual access patterns or unauthorized file access.
- Check the official vendor advisory for updates and guidance.
Affected Versions
n8n@<=1.120.0vulnerable; upgrade to1.121.0+
Resolution Guide
To upgrade n8n to a secure version, use the following commands:
npm install n8n@1.121.0
If you are using Docker, pull the latest image:
docker pull n8n@n8n:1.121.0
As a temporary mitigation, consider disabling vulnerable endpoints in your configuration:
# Example configuration to disable webhook
webhook:
disabled: true
For minimal code fixes, ensure that workflows do not expose sensitive data. For example, avoid using file system access in public workflows.
Detection & Verification
To check if your current version of n8n is vulnerable, run:
npm list n8n
To verify that you have successfully upgraded, rerun the above command and check that the version is 1.121.0 or later.
Risk and Impact
The exploitation of CVE-2026-21858 could enable remote attackers to gain unauthorized access to sensitive information stored on your server, potentially leading to further compromises depending on your deployment's configuration and workflow usage. The risk is particularly high for solo developers and small teams who may not have extensive security measures in place.
```