CVE-2026-56360: n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 1.123.18 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56360?
CVE-2026-56360 has a medium severity rating of 6.3.
How do I fix CVE-2026-56360?
To fix CVE-2026-56360, upgrade to n8n versions 1.123.18 or 2.6.2 or later.
What is the risk associated with CVE-2026-56360?
CVE-2026-56360 poses a risk of webhook forgery via unsigned POST requests, potentially allowing unauthorized workflows to be triggered.
Which software is affected by CVE-2026-56360?
CVE-2026-56360 affects n8n before versions 1.123.18 and 2.6.2.
What type of attacks can occur due to CVE-2026-56360?
Attackers can exploit CVE-2026-56360 by sending unsigned POST requests to trigger workflows with arbitrary malicious data.