CVE-2026-103253: n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with the credential's privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 1.123.80 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.39.6 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.40.1
Event History
Frequently Asked Questions
Which n8n releases need to be updated?
Update n8n versions earlier than 1.123.80, versions from 2.0.0 through earlier than 2.39.6, and versions from 2.40.0 through earlier than 2.40.1. The fixed releases identified are 1.123.80, 2.39.6, and 2.40.1.
What access does an attacker need?
The vulnerability is assessed as requiring no privileges and no user interaction. Exploitation has high attack complexity and involves injecting single quotes into the table or schema fields used by the Oracle Database node's Delete Table Drop operation.
How severe could database impact be?
An attacker can append and execute arbitrary DDL or DML statements against the connected Oracle database. The resulting impact is limited by, but can extend to, the privileges assigned to the database credential configured in n8n.