CVE-2026-103253: n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table

Published Oct 1, 2026
·
Updated

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with the credential's privileges.

Affected Software

1 affected component
n8n n8n<1.123.80, >=2.0.0<2.39.6, >=2.40.0<2.40.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 1.123.80
  2. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.39.6
  3. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.40.1

Event History

Oct 1, 2026
CVE Published
via MITRE·10:41 AM
Data Sourced
via MITRE·10:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which n8n releases need to be updated?

Update n8n versions earlier than 1.123.80, versions from 2.0.0 through earlier than 2.39.6, and versions from 2.40.0 through earlier than 2.40.1. The fixed releases identified are 1.123.80, 2.39.6, and 2.40.1.

2

What access does an attacker need?

The vulnerability is assessed as requiring no privileges and no user interaction. Exploitation has high attack complexity and involves injecting single quotes into the table or schema fields used by the Oracle Database node's Delete Table Drop operation.

3

How severe could database impact be?

An attacker can append and execute arbitrary DDL or DML statements against the connected Oracle database. The resulting impact is limited by, but can extend to, the privileges assigned to the database credential configured in n8n.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203