• News/
  • https://www.theregister.com/2026/01/08/n8n_rce_bug/

Maximum-severity n8n flaw lets randos run your automation server

The Register
·
Carly Page
·
Published Jan 8, 2026
·
Updated

A maximum-severity bug in the popular automation platform n8n has left an estimated 100,000 servers wide open to complete takeover, courtesy of a flaw so bad it doesn't even require logging in. The vulnerability, uncovered by researchers at security outfit Cyera, carries a CVSS score of 10.0 and has been dubbed "ni8mare" for good reason. Tracked as CVE-2026-21858, the flaw allows an unauthenticated attacker to execute arbitrary code on vulnerable systems, effectively handing over complete control of the affected environment. There is no workaround other than patching, and users are urged to upgrade to n8n version 1.121.0 or later. n8n is a self-hosted, open source automation tool that many organizations use to stitch together chat apps, forms, cloud storage, databases, and third-party APIs. It claims more than 100 million Docker pulls, with millions of users and thousands of companies using it to automate everything from internal workflows to customer-facing processes. According to Cyera, the root of the problem lies in how n8n processes webhooks – the mechanism used to kick off workflows when data arrives from external systems such as web forms, messaging platforms, or notification services. By abusing a so-called "Content-Type Confusion" issue, an attacker can manipulate HTTP headers to overwrite internal variables used by the application. That, in turn, allows them to read arbitrary files from the underlying system and escalate the attack to full remote code execution. In ...

Read full article

Affected Software

1 affected component
n8n n8n>=1.121.0

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the automation platform n8n that allows unauthorized users to take control of servers without logging in.

2

What is the severity level of the n8n flaw?

The vulnerability has a maximum severity level with a CVSS score of 10.0.

3

How many n8n servers are estimated to be affected by this vulnerability?

The article estimates that approximately 100,000 n8n servers are vulnerable to this exploit.

4

What is required for an attacker to exploit the n8n flaw?

Exploiting the n8n flaw does not require any authentication or login credentials.

5

Who uncovered the n8n vulnerability?

The vulnerability was discovered by researchers from a security outfit named Cyera.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203