• News/
  • https://www.bleepingcomputer.com/news/security/max-severity-ni8mare-flaw-impacts-nearly-60-000-n8n-instances/

Max severity Ni8mare flaw impacts nearly 60,000 n8n instances

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 12, 2026
·
Updated

Nearly 60,000 n8n instances exposed online remain unpatched against a maximum-severity vulnerability dubbed "Ni8mare." n8n is an open-source workflow automation platform that allows users to connect different applications and services via pre-built connectors and a visual, node-based interface to automate repetitive tasks without writing code. The automation platform is widely used in AI development to automate data ingestion and build AI agents and RAG pipelines. It has over 100 million pulls on Docker Hub and over 50,000 weekly downloads on npm. Since n8n serves as a central automation hub, it often stores API keys, OAuth tokens, database credentials, cloud storage access, CI/CD secrets, and business data, making it an attractive target for threat actors. Tracked as CVE-2026-21858, this security flaw stems from an improper input validation weakness that allows remote, unauthenticated attackers to take control over locally deployed n8n instances after gaining access to files on the underlying server. "A vulnerable workflow could grant access to an unauthenticated remote attacker. This could potentially result in exposure of information stored on the system and may enable further compromise depending on deployment configuration and workflow usage," the n8n team explained. "An n8n instance is potentially vulnerable if it has an active workflow with a Form Submission trigger accepting a file element, and a Form Ending node returning a binary file." ​Cyera researchers who disco...

Read full article

Affected Software

1 affected component
n8n n8n<1.121.0

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability known as 'Ni8mare' affecting nearly 60,000 online instances of the n8n workflow automation platform.

2

What severity level is assigned to the Ni8mare vulnerability?

The Ni8mare vulnerability is classified as a maximum-severity flaw.

3

How many n8n instances are thought to be affected by the Ni8mare flaw?

Approximately 60,000 n8n instances are exposed online and remain unpatched.

4

What specific version of n8n is impacted by the Ni8mare vulnerability?

The affected version of n8n is up to 1.121.0.

5

What is the function of the n8n platform that is impacted by this vulnerability?

n8n is an open-source workflow automation platform that connects various applications and services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203