https://reddit.com/r/netsec/comments/1q6iw0y/ni8mare_unauthenticated_remote_code_execution_in/: Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)
Published Jan 7, 2026
·Updated
Affected Software
1 affected component
npm/n8n
CVE-2026-21858 has a critical severity rating with a CVSS score of 10.0.
To fix CVE-2026-21858, update to the latest version of n8n that includes the security patch.
CVE-2026-21858 allows unauthorized remote code execution, enabling attackers to take control of affected n8n instances.
CVE-2026-21858 affects the n8n workflow automation tool.
CVE-2026-21858 is estimated to impact around 100,000 n8n servers globally.