CVE-2026-1470Disclosure(n8n / n8n)

HIGHCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 16 mentions and remains active

Immediate actions

  • Patch n8n n8n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 42 mentions across 9 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 33 signals
  • Disclosure: 21 classified signals
  • Peaked 6d ago at 16 mentions (2026-01-29); latest day: 1
  • 42 total mentions across 9 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline42 mentions / 9d
0481216Mentions · 2026-01-27: 1Mentions · 2026-01-28: 9Mentions · 2026-01-29: 16Mentions · 2026-01-30: 8Mentions · 2026-02-01: 2Mentions · 2026-02-02: 2Mentions · 2026-02-03: 2Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1PoC Mentioned / Linked · 2026-01-28: 2PoC Mentioned / Linked · 2026-01-29: 3PoC Mentioned / Linked · 2026-02-01: 1Exploit Tool / Code · 2026-01-28: 1Exploit Tool / Code · 2026-01-29: 2Active Exploitation · 2026-02-01: 1Patch / Workaround · 2026-01-28: 5Patch / Workaround · 2026-01-29: 11Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-02-05: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 7Technical Details · 2026-01-29: 13Technical Details · 2026-01-30: 6Technical Details · 2026-02-02: 2Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 101-2701-2801-2901-3002-0102-0202-0302-0402-05
Signal classification5 categories
Disclosure
2150.0%
Patch
1638.1%
PoC
37.1%
General
12.4%
Active Exploitation
12.4%
Referenced assets34 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-01-289
Disclosure5Patch3PoC1
2026-01-2916
Disclosure4Patch11PoC1
2026-01-308
Disclosure6General1Patch1
2026-02-012
Active Exploitation1PoC1
2026-02-022
Disclosure2
2026-02-032
Disclosure2
2026-02-041
Disclosure1
2026-02-051
Patch1
Full discourse20 posts
  • Rishi@rxerium
    PoC

    🚨 2 new vulnerability scripts created for the n8n vulnerabilities disclosed today: CVE-2026-1470: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-1470.yaml CVE-2026-0863: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-0863.yaml Happy hunting. https://t.co/v8PXwBjKQ8

    Post summary

    Two new exploit scripts for the n8n CVEs CVE-2026-1470 and CVE-2026-0863 have been published on GitHub, providing PoC templates for these vulnerabilities.

    473142121126.1K
    3.1K followersView on X
  • ZoomEye@zoomeye_team
    Patch

    🚨 CVE-2026-1470 (CVSS 9.9): Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node. n8n is vulnerable to a critical remote code execution flaw in its Expression sandbox, allowing authenticated users to bypass isolation and execute arbitrary code with the n8n process’s privileges. Search by vul.cve Filter 👉 vul.cve="CVE-2026-1470" ZoomEye Dork 👉 app="n8n" 264k+ exposed instances. ZoomEye Link: https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjYtMTQ3MCI=&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260128 Refer: https://github.com/n8n-io/n8n/commit/aa4d1e5825829182afa0ad5b81f602638f55fa04 #ZoomEye #NetSec #OSINT #CyberSecurity #n8n #LowCodeSecurity #APIsecurity #SupplyChainSecurity

    Post summary

    The tweet reports a critical RCE vulnerability in n8n’s Expression sandbox, provides technical details, and cites a GitHub commit that offers a patch, but no evidence of active exploitation or PoC is mentioned.

    225075397.8K
    11.9K followersView on X
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-1470 (CVSS score: 9.9): Critical n8n Flaw Allows Remote Code Execution. 🔥PoC :https://research.jfrog.com/vulnerabilities/n8n-expression-node-rce/ 📊 981K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22n8n%22 👇Query HUNTER : http://product.name="n8n" 📰Refer:https://thehackernews.com/2026/01/two-high-severity-n8n-flaws-allow.html https://securityonline.info/sandbox-shattered-critical-n8n-flaw-cvss-9-9-allows-remote-code-execution/ https://www.bleepingcomputer.com/news/security/new-sandbox-escape-flaw-exposes-n8n-instances-to-rce-attacks/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    Alert for CVE‑2026‑1470, a critical n8n flaw that allows remote code execution, with a publicly shared PoC but no active exploitation reports, patch details, or debunking claims.

    010156227.5K
    25.4K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-1470 (CVSS 9.9): "Sandbox Shattered" in n8n A critical vulnerability allows attackers to escape the n8n sandbox and execute arbitrary code on the host server (RCE). 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJuOG4i 🎯599k+ Results are found on the https://en.fofa.info nearly year. FOFA Query: app="n8n" 🔖Refer: https://securityonline.info/sandbox-shattered-critical-n8n-flaw-cvss-9-9-allows-remote-code-execution/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The tweet announces CVE-2026-1470 as a high‑severity sandbox escape in n8n that allows arbitrary code execution, but it does not provide a PoC, exploit code, or patch information.

    11002373.1K
    13.6K followersView on X
  • blueblue@piedpiper1616
    Disclosure

    Achieving Remote Code Execution on n8n Via Sandbox Escape - CVE-2026-1470 & CVE-2026-0863 - JFrog Security Research - https://research.jfrog.com/post/achieving-remote-code-execution-on-n8n-via-sandbox-escape/

    Post summary

    The article announces remote code execution vulnerabilities in n8n via sandbox escape, identified as CVE‑2026‑1470 and CVE‑2026‑0863, without evidence of active exploitation or mitigation.

    04021122.0K
    5.5K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    n8n - CVE-2026-1470 et CVE-2026-0863 : deux nouvelles failles patchées, comment se protéger ? 👇 Les détails dans l'article de Florian : - https://www.it-connect.fr/n8n-cve-2026-1470-et-cve-2026-0863-patchs-de-securite/ #n8n #infosec #cybersecurite https://t.co/NsBGGCCWZs

    Post summary

    The tweet announces that two newly discovered n8n CVEs have been patched and directs readers to an article with protection guidance.

    03041538
    10.9K followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Disclosure

    Investigadores reportaron una vulnerabilidad crítica en n8n (CVE-2026-1470, CVSS 9.9) que, bajo ciertas condiciones, podría permitir ejecución remota de código mediante el sistema de expresiones. El fallo afectaría a múltiples versiones y potencialmente expondría miles de servicios, por lo que el riesgo debe considerarse alto mientras se evalúa su alcance real.

    Post summary

    Investigadores han divulgado CVE-2026-1470, una vulnerabilidad crítica en n8n que permite la ejecución remota de código a través del sistema de expresiones, afectando varias versiones y representando un riesgo alto hasta que se evalúe su alcance real.

    02040279
    3.8K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    n8nでリモートコード実行が可能になる脆弱性(CVE-2026-1470,CVE-2026-0863)|セキュリティ対策Lab https://rocket-boys.co.jp/security-measures-lab/remote-code-execution-vulnerabilities-in-n8n-cve-2026-1470-and-cve-2026-0863/ "業務自動化基盤は認証情報や社内APIへのアクセス権を内包しやすく、侵害されると横展開が起きやすいため、情報システム部門としては優先度高く扱うべき類型です"

    Post summary

    The article discloses remote code execution vulnerabilities (CVE-2026-1470, CVE-2026-0863) affecting n8n, emphasizing their severity but providing no PoC, exploit code, or patch details.

    10101463
    3.4K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical n8n Flaws Let Attackers Bypass Sandbox and Hijack AI Automation Workflows JFrog disclosed two n8n vulnerabilities (CVE-2026-1470, CVSS 9.9; CVE-2026-0863, CVSS 8.5) that can bypass sandbox controls and enable full takeover/RCE on vulnerable cloud or self-hosted deployments, exposing stored credentials, API keys, and connected systems. Patch/upgrade affected versions prior to 1.123.17/2.4.5/2.5.1 (CVE-2026-1470) and 1.123.14/2.3.5/2.4.2 (CVE-2026-0863). 🎯 Target: Global/Enterprises using n8n (AI workflow automation) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.darkreading.com/vulnerabilities-threats/critical-flaws-n8n-compromise-customer-security

    Post summary

    JFrog disclosed two critical n8n vulnerabilities enabling sandbox bypass and full RCE, providing CVE identifiers, CVSS scores and specific patch recommendations for affected versions.

    1002069
    196 followersView on X
  • Security Boulevard@securityblvd
    Disclosure

    JFrog security researchers have exposed two critical vulnerabilities (CVE-2026-1470, rated 9.9; and CVE-2026-0863, rated 8.5) in the n8n workflow automation platform. Here's what you need to know 👉 https://buff.ly/EwBBrj8 #Vulnerability #CVE #Cybersecurity #JFrog #n8n

    Post summary

    JFrog security researchers disclosed two critical CVEs (CVE‑2026‑1470 and CVE‑2026‑0863) affecting the n8n platform with high severity scores, but no PoC, exploit, or patch details are provided.

    01010101
    7.0K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Critical vulnerabilities including n8n CVE-2026-1470 and Microsoft Office CVE-2026-21509 expose software, networks, and OT to risks. State-backed groups exploit legacy flaws impacting infrastructures like Poland’s power grid. #Poland #RemoteCode https://ift.tt/xn4PsV9

    Post summary

    The post reports that state-backed actors are actively exploiting CVE-2026-1470 and CVE-2026-21509 against critical infrastructure, notably Poland’s power grid. No evidence of patches, PoC, or detailed exploit code is provided.

    00020530
    3.6K followersView on X
  • Compunet@CompunetChile
    Patch

    🚨 Alerta de Ciberseguridad | CompuNet Nuestro Blueteam SOC detectó vulnerabilidades críticas en n8n (CVE-2026-1470 / CVE-2026-0863) que permiten ejecución de código y compromiso total de instancias. 👉 Actualiza y mitiga de inmediato. #Ciberseguridad #AlertaSeguridad #SOC https://t.co/iWiwy4Kw96

    Post summary

    A CompuNet SOC alert highlights critical CVEs in n8n that allow code execution and total instance compromise, urging immediate updates and mitigation.

    0101060
    53 followersView on X
  • SOCRadar®@socradar
    Patch

    🚨 Two severe sandbox escape flaws in #n8n automation platform (CVE-2026-1470 & CVE-2026-0863) enable authenticated users to execute arbitrary code. 🔹 Affects JS & Python execution 🔹 #RCE risk on host 🔹 Patches available 🔍: https://socradar.io/blog/cve-2026-1470-0863-sandbox-n8n-rce/

    Post summary

    The post highlights two sandbox escape vulnerabilities in n8n that allow authenticated users to execute arbitrary code and notes that patches are available to address the issue.

    01010176
    5.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『In both cases, exploitation resulted in remote code execution (RCE) by abusing gaps in the AST sanitization logic.』 Achieving Remote Code Execution on n8n Via Sandbox Escape - CVE-2026-1470 & CVE-2026-0863 https://research.jfrog.com/post/achieving-remote-code-execution-on-n8n-via-sandbox-escape/

    Post summary

    The post discloses that CVE-2026-1470 and CVE-2026-0863 allow remote code execution in n8n through gaps in AST sanitization, without mentioning active attacks or available patches.

    00020554
    6.7K followersView on X
  • Red Hot Cyber@redhotcyber
    Disclosure

    Allerta n8n: Scoperte due falle RCE critiche (CVE-2026-1470). Aggiorna ora! 📌 Link all'articolo : https://www.redhotcyber.com/post/allerta-n8n-scoperte-due-falle-rce-critiche-cve-2026-1470-aggiorna-ora/ #redhotcyber #news #cybersecurity #hacking #vulnerabilita #sicurezzainformatica #n8n #codicearbitrario https://t.co/NaTMQnO5IL

    Post summary

    The tweet reports the discovery of two critical RCE vulnerabilities (CVE‑2026‑1470) in n8n and urges users to update, but it does not provide exploit details, patches, or evidence of active exploitation.

    01010156
    4.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    n8n Sandbox の脆弱性 CVE-2026-1470/0863 が FIX:サンドボックス回避と RCE https://iototsecnews.jp/2026/01/28/critical-and-high-severity-n8n-sandbox-flaws-allow-rce/ ワークフロー自動化ツールとして広く利用されている n8n において、深刻な脆弱性が2件発見されました。これらの脆弱性を悪用する攻撃者は、カスタムコードを実行するためのサンドボックス (隔離環境) を突破し、サーバ上で任意のコマンドを実行できてしまいます。 この脆弱性を悪用するには、ワークフローを作成/編集する権限が必要ですが、組織内の正規ユーザーであれば、誰でもサーバー全体を乗っ取れる可能性があるため、内部不正やアカウント情報の漏洩が致命的な被害に直結します。ご利用のチームは、ご注意ください。 #CVE20260863 #CVE20261470 #n8n #Sandbox #Vulnerability

    Post summary

    n8n’s sandbox bypass vulnerabilities (CVE-2026-1470 / 0863) allow RCE and have been fixed, but no exploit code or evidence of active exploitation is reported.

    01000163
    483 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    n8nでリモートコード実行が可能になる脆弱性(CVE-2026-1470,CVE-2026-0863) https://rocket-boys.co.jp/security-measures-lab/remote-code-execution-vulnerabilities-in-n8n-cve-2026-1470-and-cve-2026-0863/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces that n8n is vulnerable to remote code execution via CVE-2026-1470 and CVE-2026-0863, but provides no PoC, exploit code, or mitigation details.

    00010102
    318 followersView on X
  • 𓊈𒆜🅲🆁🅸🆂🆃🅸🅰🅽 𒆜𓊉@Cris7ianJCC
    Patch

    Actualizaciones recomendadas: - Para corregir CVE-2026-1470, actualiza a las versiones 1.123.17, 2.4.5 o 2.5.1. - Para CVE-2026-0863, se sugieren las versiones 1.123.14, 2.3.5 o 2.4.2.

    Post summary

    This advisory lists patch versions to address CVE-2026-1470 and CVE-2026-0863, with no further exploit or technical details.

    1000039
    664 followersView on X
  • 𓊈𒆜🅲🆁🅸🆂🆃🅸🅰🅽 𒆜𓊉@Cris7ianJCC
    Disclosure

    1.- CVE-2026-1470 (Puntuación CVSS: 9.9): Tipo: Inyección eval. Descripción: Permite a un usuario autenticado eludir el mecanismo de sandbox del motor de expresiones de n8n y ejecutar código JavaScript arbitrario en el nodo principal.

    Post summary

    The text announces CVE-2026-1470 as a high‑severity eval injection in n8n, allowing authenticated users to escape the sandbox and execute arbitrary JavaScript.

    1000060
    664 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-40551 2 - CVE-2026-24858 3 - CVE-2025-8088 4 - CVE-2025-15467 5 - CVE-2026-1470 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without offering any additional details or context.

    00010213
    1.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.5.0node.js-

Explore more