CVE-2026-27493Patch(n8n / n8n)

HIGHCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch n8n n8n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and evaluate arbitrary n8n expressions by submitting crafted form data. When chained with an expression sandbox escape, this could escalate to remote code execution on the n8n host. The vulnerability requires a specific workflow configuration to be exploitable. First, a form node with a field interpolating a value provided by an unauthenticated user, e.g. a form submitted value. Second, the field value must begin with an `=` character, which caused n8n to treat it as an expression and triggered a double-evaluation of the field content. There is no practical reason for a workflow designer to prefix a field with `=` intentionally — the character is not rendered in the output, so the result would not match the designer's expectations. If added accidentally, it would be noticeable and very unlikely to persist. An unauthenticated attacker would need to either know about this specific circumstance on a target instance or discover a matching form by chance. Even when the preconditions are met, the expression injection alone is limited to data accessible within the n8n expression context. Escalation to remote code execution requires chaining with a separate sandbox escape vulnerability. The issue has been fixed in n8n versions 2.10.1, 2.9.3, and 1.123.22. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations. Review usage of form nodes manually for above mentioned preconditions, disable the Form node by adding `n8n-nodes-base.form` to the `NODES_EXCLUDE` environment variable, and/or disable the Form Trigger node by adding `n8n-nodes-base.formTrigger` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-95

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 24 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 20 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 10d ago at 5 mentions (2026-02-26); latest day: 1
  • 24 total mentions across 11 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline24 mentions / 11d
01345Mentions · 2026-02-26: 5Mentions · 2026-02-27: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 3Mentions · 2026-03-13: 3Mentions · 2026-03-20: 1Mentions · 2026-03-27: 1Mentions · 2026-04-14: 5Mentions · 2026-04-15: 2Mentions · 2026-04-24: 1Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-04-14: 3PoC Mentioned / Linked · 2026-04-24: 1Exploit Tool / Code · 2026-04-14: 1Active Exploitation · 2026-03-12: 1Patch / Workaround · 2026-02-26: 3Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-12: 3Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-02-26: 4Technical Details · 2026-02-27: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-14: 4Technical Details · 2026-04-15: 2Technical Details · 2026-04-24: 102-2602-2703-1103-1203-1303-2003-2704-1404-1504-2408-30
Signal classification6 categories
Patch
937.5%
Disclosure
833.3%
General
312.5%
PoC
28.3%
Active Exploitation
14.2%
Exploit
14.2%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-02-265
Disclosure2General1Patch2
2026-02-271
Patch1
2026-03-111
Patch1
2026-03-123
Active Exploitation1Patch2
2026-03-133
Disclosure3
2026-03-201
Patch1
2026-03-271
Disclosure1
2026-04-145
Disclosure1Exploit1General1PoC2
2026-04-152
Disclosure1Patch1
2026-04-241
Patch1
2026-08-301
General1
Full discourse20 posts
  • NullSecurityX@NullSecurityX
    Exploit

    Zero Click Unauthenticated RCE in n8n (CVE-2026-27493) The chain exploitation method is: Allow User input SSTI exploitation e.g. {{7*7}} ={{$node["NodeName"].constructor.constructor('return process.mainModule.require("child_process").execSync("id ").toString()')()}} https://t.co/yn1czhJGIS

    Post summary

    The post discloses a zero‑click unauthenticated RCE in n8n with a concrete SSTI exploit snippet and a link to a PoC; it does not indicate active exploitation or patch status.

    780047629136.8K
    12.1K followersView on X
  • DarkShadow@darkshadow2bd
    PoC

    Zero Click Unauthenticated RCE in n8n (CVE-2026-27493) The chain exploitation method is: 1. Allow User input 2. Render the user input on browser 3. SSTI exploitation e.g. {{7*7}} 4. SSTI to RCE payload e.g. ={{$node["NodeName"].constructor.constructor('return process.mainModule.require("child_process").execSync("id").toString()')()}} For more don't forget to join my BugBounty telegram channel http://t.me/ShellSec

    Post summary

    The message discloses a zero‑click unauthenticated RCE in n8n (CVE‑2026‑27493) and supplies a concrete SSTI-to-RCE payload, but does not report active exploitation or provide a patch.

    1190114798.7K
    7.4K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na kritické zranitelnosti v n8n, CVE-2026-27493 a CVE-2026-27577. CVE-2026-27493: Zranitelnost v n8n Form nodes umožňuje neautentizovanému útočníkovi bez jakékoliv interakce uživatele provést vzdálené spuštění libovolného kódu. Chyba spočívá v mechanismu dvojité evaluace výrazů: pokud vícekrokový formulář zobrazuje uživatelský vstup zpět odesílateli přes HTML renderovací krok, vstup je dvakrát vyhodnocen jako výraz. Útočník tak může vložit škodlivý výraz, který vede k vykonání shell příkazů na serveru. Může tak dojít k plnému převzetí systému a potenciálnímu úniku citlivých přihlašovacích údajů. Útok je možný bez autentizace a je spustitelný přes veřejné endpointy vícekrokových formulářů. CVE-2026-27577: Zranitelnost v kompilátoru výrazů n8n umožňuje autentizovanému útočníkovi obejít sandbox pomocí chybějícího přepisování některých struktur v AST, například SpreadElement. Kvůli této chybě nejsou určité výrazy správně transformovány, což vede k úniku ze sandboxu a přímému přístupu k prostředí Node.js. Útočník tak může interagovat se systémovými procesy a získat rozšířená oprávnění. 📌Doporučujeme n8n aktualizovat na verzi 2.10.1, 2.9.3, 1.123.22, případně vyšší.

    Post summary

    The post warns of two critical CVEs in n8n, details their technical exploitation vectors, and urges users to upgrade to specified patched versions.

    03060785
    4.2K followersView on X
  • Brut 🇮🇳@wtf_yodhha
    Disclosure

    🚨Zero Click Unauthenticated RCE in n8n (CVE-2026-27493) ✅ Join Telegram For More Content: http://t.me/brutsecurity 📖 Your Bugbounty Journey Starts Here → http://topmate.io/saumadip/2009859 🎓 Enroll Now → http://wa.link/brutsecurity #CyberSecurity #BugBounty #EthicalHacking #Infosec https://t.co/qSSBxzyvcK

    Post summary

    The post announces a newly discovered zero‑click unauthenticated remote code execution vulnerability (CVE‑2026‑27493) affecting n8n, without providing PoC, exploit code, active exploitation evidence, or mitigation details.

    010341.2K
    7.2K followersView on X
  • Kevin Poireault@kpoireault
    Disclosure

    𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐙𝐞𝐫𝐨-𝐂𝐥𝐢𝐜𝐤 𝐅𝐥𝐚𝐰 𝐢𝐧 𝐧𝟖𝐧 𝐀𝐥𝐥𝐨𝐰𝐬 𝐅𝐮𝐥𝐥 𝐒𝐞𝐫𝐯𝐞𝐫 𝐂𝐨𝐦𝐩𝐫𝐨𝐦𝐢𝐬𝐞 Researchers at @Pillar_sec have found 2 new critical vulnerabilities in self-hosted and cloud n8n deployments, including CVE-2026-27493 ⤵️ https://www.infosecurity-magazine.com/news/critical-zeroclick-flaw-n8n-pillar/ https://t.co/ZeFVegZfbs

    Post summary

    Researchers at Pillar Security announced two new critical vulnerabilities in self‑hosted and cloud n8n deployments, including CVE‑2026‑27493, but did not provide further technical or exploit details.

    0001155
    1.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    The Unauthenticated Endpoint: Form Node Double-Evaluation (CVE-2026-27493) The Sandbox Escape: SpreadElement Bypass (CVE-2026-27577) Zero Click Unauthenticated RCE in n8n: A Contact Form That Executes Shell Commands https://www.pillar.security/blog/zero-click-unauthenticated-rce-in-n8n-a-contact-form-that-executes-shell-commands

    Post summary

    The passage lists two new CVEs and highlights a zero-click RCE in n8n, directing readers to a blog post that likely details the vulnerability.

    001101.1K
    6.7K followersView on X
  • Modat@modat_magnify
    Active Exploitation

    CVE-2025-68613 / CVE-2026-27577 / CVE-2026-27493  ⚠️ n8n Workflow Automation – Actively Exploited RCE (CISA KEV)  CISA has added CVE-2025-68613 (CVSS 10.0) to its KEV catalogue following evidence of active exploitation impacting n8n.  The flaw is an improper control of dynamically managed code resources vulnerability in n8n’s workflow expression evaluation system that allows authenticated attackers to execute arbitrary code with the privileges of the n8n process.  This follows CVE-2026-27577 (CVSS 9.4), an expression sandbox escape enabling authenticated RCE, and CVE-2026-27493 (CVSS 9.5), an unauthenticated expression injection flaw in Form nodes. When chained, attackers may execute commands and extract stored credentials.  Fixed in 1.120.4 / 1.121.1 / 1.122.0 (CVE-2025-68613) and 2.10.1 / 2.9.3 / 1.123.22 (CVE-2026-27577 and -27493). Patch immediately.  Modat Magnify Query:  web.title~"http://n8n.io - Workflow Automation" tag!=honeypot  The platform:  https://magnify.modat.io/  #threatintel #vulnerability #CVE202568613 #CVE202627577 #CVE202627493 #n8n #RCE #CISA #KEV #infosec #ModatMagnify

    Post summary

    The post confirms active exploitation of CVE‑2025‑68613 in n8n, details the RCE flaw, and provides the specific patched versions for remediation.

    10010239
    291 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『allow an unauthenticated attacker to inject and evaluate arbitrary n8n expressions by submitting crafted form data.』 CVE-2026-27493 n8n has Unauthenticated Expression Evaluation via Form Node https://github.com/advisories/GHSA-75g8-rv7v-32f7

    Post summary

    The advisory discloses an unauthenticated expression evaluation flaw in n8n's Form Node, allowing attackers to inject arbitrary expressions via crafted form data.

    01010416
    6.7K followersView on X
  • Pillar Security@Pillar_sec
    Patch

    Pillar's research team found a zero-click, unauthenticated RCE in @n8n_io (CVE-2026-27493, CVSS 9.5 Critical & CVE-2026-27577 CVSS 9.4 Critical). No account. No authentication. A browser and a contact form is all it takes to execute shell commands on the server and decrypt every credential stored in the platform. We scanned for publicly accessible n8n form endpoints and found over 50,000 potentially vulnerable forms exposed to the internet. We worked with the n8n team to fix it. If you're self-hosting, update to the latest version now. Read more: https://www.pillar.security/blog/zero-click-unauthenticated-rce-in-n8n-a-contact-form-that-executes-shell-commands

    Post summary

    Pillar Security disclosed a critical zero‑click RCE in n8n, identified more than 50,000 vulnerable forms, and urged self‑hosted users to update to the latest version to mitigate the issue.

    0001075
    151 followersView on X
  • Outis@xfeylesof
    Disclosure

    Zero Click Unauthenticated RCE in n8n (CVE-2026-27493) #BugBounty #CyberSecurity

    Post summary

    A new zero‑click, unauthenticated remote code execution vulnerability in n8n (CVE‑2026‑27493) has been announced.

    0000133
    1.8K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 Zero-Click Nightmare: How a Simple {{77}} in n8n Grants Unauthenticated RCE (#CVE-2026-27493) + Video https://undercodetesting.com/zero-click-nightmare-how-a-simple-77-in-n8n-grants-unauthenticated-rce-cve-2026-27493-video/ Educational Purposes!

    Post summary

    The tweet shares a video that demonstrates a zero‑click, unauthenticated remote code execution vulnerability in n8n (CVE‑2026‑27493), providing a proof of concept but lacking exploit code, patch information, or evidence of active exploitation.

    0001042
    492 followersView on X
  • iototsecnews@iototsecnews
    Patch

    n8n の脆弱性 CVE-2026-27577/27493 が FIX:サンドボックス・エスケープによる乗っ取りの可能性 https://iototsecnews.jp/2026/03/13/critical-zero-click-flaw-in-n8n-allows-full-server-compromise/ AI エージェント/ワークフローを支えるオープンソース・プラットフォーム n8n に、サーバの完全な乗っ取りを許す 2 件の深刻な脆弱性が発見されました。n8n が多様な外部サービス (AWS/GitHub/Slack など) の認証情報の保管庫として機能しているため、サンドボックスの突破により、接続されている全システムへの鍵が流出するという、危険な状況にあります。 脆弱性 CVE-2026-27577 (CVSS v4.0:9.4) は、ワークフロー内で使用される式のコンパイル処理における不備に起因します。認証済みユーザーが、悪意の式を挿入することで、安全に分離されているはずの実行環境が回避され、サーバ上での任意の OS コマンド実行が可能になります。 さらに深刻なのが、脆弱性 CVE-2026-27493 (CVSS v4.0:9.5) です。この脆弱性は、n8nの Formノードにおける入力値の二重評価という設計ミスに起因します。この攻撃では、認証が不要であるため、アカウントを持っていない攻撃者であっても、公開されている問い合わせフォームなどの入力欄に特定のコードを書き込み、サーバを遠隔操作できてしまいます。ご利用のチームは、ご注意ください。 #CVE202627493 #CVE202627577 #n8n #Vulnerability

    Post summary

    The article announces that two high‑severity vulnerabilities in the n8n platform were discovered and have been fixed, outlining technical details, but does not report active exploitation or provide a PoC.

    01000184
    484 followersView on X
  • Eilon Cohen@NoShitOasis
    Patch

    Welcome my new latest findings at @Pillar_sec: - Unauthenticated Expression Evaluation via Form Node in n8n (CVE-2026-27493, CVSS v4 9.5) - Expression Sandbox Escape Leading to RCE in n8n (CVE-2026-27577, CVSS v4 9.4) Highly recommended to update n8n to patched versions.

    Post summary

    Two high‑severity CVEs in n8n are disclosed, and the author recommends applying the available patches.

    1000070
    178 followersView on X
  • Ankit@ankitkat_042
    General

    cve-2026-27493 ka payload nhi mil raha hai dosto

    Post summary

    The user reports that they cannot find a payload for CVE-2026-27493; no further exploitation, patch, or technical details are provided.

    0000083
    288 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Defending Against Critical n8n RCE Flaws: Patching Guide for CVE-2026-27577 and… "Workflow automation tools like n8n have become essential components of modern IT…" 🔗 https://securityarsenal.com/blog/defending-against-critical-n8n-rce-flaws-patching-guide-for-cve-2026-27577-and-cve-2026-27493 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The tweet promotes a blog article that offers a patching guide for the n8n RCE vulnerabilities CVE-2026-27577 and CVE-2026-27493.

    0000026
    10 followersView on X
  • Outis@xfeylesof
    General

    CVE-2026-27493 #bugbounty #cybersecurity

    Post summary

    The post merely references CVE-2026-27493 with no additional context, indicating a generic mention without evidence of PoC, exploitation, patch, or technical details.

    0000023
    1.8K followersView on X
  • ARCHIE@archie_sham
    Disclosure

    🚨🚨Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials🚨🚨 CVE-2026-27577 (CVSS score: 9.4) CVE-2026-27493 (CVSS score: 9.5) #n8n #CVE #Alert #Cybersecurity https://t.co/PWpyNkfCmP

    Post summary

    The tweet announces two new critical n8n CVEs that enable remote code execution and credential exposure, but provides no proof‑of‑concept, exploit code, or patch information.

    00000101
    228 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Second-order Expression Injection Vulnerability in #n8n. CVE-2026-27493 CVSS: 9.5. This vulnerability could escalate to remote code execution when chained with an expression sandbox escape. #Patch #Patch #Patch

    Post summary

    A new, high‑severity second‑order expression injection vulnerability (CVE‑2026‑27493) has been disclosed in n8n, potentially enabling remote code execution, but no PoC, exploit code, or patch details are provided.

    00000251
    7.2K followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical n8n vulnerabilities could lead to RCE + potential credential exposure (CVE-2026-27577, CVE-2026-27493). Patch to 2.10.1 / 2.9.3 / 1.123.22 ASAP. https://vulert.com/blog/critical-n8n-vulnerabilities-rce-credential/ #CyberSecurity #AppSec #n8n #Vulert

    Post summary

    Critical n8n vulnerabilities (CVE‑2026‑27577 and CVE‑2026‑27493) could enable remote code execution and credential exposure; users are advised to apply the listed patches immediately.

    0000042
    124 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Two critical n8n vulnerabilities, CVE-2026-27577 and CVE-2026-27493, allowed remote code execution and exposure of credentials. Patches released in versions 2.10.1, 2.9.3, and 1.123.22. #WorkflowSecurity #RemoteCodeExecution #Germany https://ift.tt/tsMCkAW

    Post summary

    Two critical vulnerabilities in n8n (CVE-2026-27577 and CVE-2026-27493) allow remote code execution and credential exposure. Patches are available in versions 2.10.1, 2.9.3, and 1.123.22.

    00000131
    3.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more