CVE-2026-27495Patch(n8n / n8n)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in the JavaScript Task Runner sandbox to execute arbitrary code outside the sandbox boundary. On instances using internal Task Runners (default runner mode), this could result in full compromise of the n8n host. On instances using external Task Runners, the attacker might gain access to or impact other task executed on the Task Runner. Task Runners must be enabled using `N8N_RUNNERS_ENABLED=true`. The issue has been fixed in n8n versions 2.10.1, 2.9.3, and 1.123.22. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations. Limit workflow creation and editing permissions to fully trusted users only, and/or use external runner mode (`N8N_RUNNERS_MODE=external`) to limit the blast radius. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-02-26); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-02-26: 3Mentions · 2026-02-27: 2Mentions · 2026-03-03: 2Mentions · 2026-03-05: 1Mentions · 2026-03-07: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-02-27: 2Patch / Workaround · 2026-03-11: 1Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 2Technical Details · 2026-03-03: 2Technical Details · 2026-03-11: 102-2602-2703-0303-0503-0703-11
Signal classification3 categories
Patch
550.0%
General
330.0%
Disclosure
220.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-263
Disclosure1Patch2
2026-02-272
Patch2
2026-03-032
Disclosure1General1
2026-03-051
General1
2026-03-071
General1
2026-03-111
Patch1
Full discourse10 posts
  • The Shadowserver Foundation@Shadowserver
    General

    We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-68613%2B&tag=cve-2025-68668%2B&tag=cve-2026-21858%2B&tag=cve-2026-21877%2B&tag=cve-2026-25053%2B&tag=cve-2026-25056%2B&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on Top affected: US, Germany & France. https://t.co/mEUZ9Is6bf

    Post summary

    The post announces the addition of CVE‑2026‑27495 to their n8n RCE scanning list, provides a dashboard link for tracking, and notes affected regions, but does not mention PoC, exploit code, active exploitation, patches, or false positives.

    112032154.3K
    21.6K followersView on X
  • Jintao Zhang 张晋涛@zhangjintao9020
    Patch

    最近 n8n 爆出来了 4 个高危漏洞 CVE-2026-27495/CVE-2026-27497/CVE-2026-27498/CVE-2026-27577 一个 9.0,三个 9.4。 基本的影响都是允许执行远程命令。 这个事情倒是也不能说完全怪 n8n,大多数这种场景下的工具都会有类似的情况,各种 sandbox 逃逸,大家如果有自己部署的 n8n 记得升级到最新版

    Post summary

    Four high‑severity CVEs (CVE‑2026‑27495, CVE‑2026‑27497, CVE‑2026‑27498, CVE‑2026‑27577) were found in n8n, allowing remote command execution; users are urged to upgrade to the latest releases.

    011724.9K
    12.5K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple Critical Vulnerabilities in #n8n. CVE-2026-27497 CVE-2026-27577 CVE-2026-27495 CVSS: 9.4. These vulnerabilities can lead to a full compromised host https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-n8n-patch-immediately #Patch #Patch #Patch

    Post summary

    Multiple critical CVEs in n8n (CVE-2026-27497, 27577, 27495) are highlighted with a CVSS of 9.4, and users are urged to patch immediately per the linked advisory.

    02210707
    7.2K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Disclosure

    IP data on vulnerable instances is tagged 'n8n' & with a cve tag (like cve-2026-27495) in our Vulnerable HTTP reporting - https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ Latest n8n critical RCE vulns (all covered with above tag): https://github.com/n8n-io/n8n/security/advisories/GHSA-wxx7-mcgf-j869 https://github.com/n8n-io/n8n/security/advisories/GHSA-vpcf-gvg4-6qwr https://github.com/n8n-io/n8n/security/advisories/GHSA-jjpj-p2wh-qf23

    Post summary

    The post lists recent critical RCE vulnerabilities for n8n, tagging them in Shadowserver’s Vulnerable HTTP reporting and linking to GitHub advisories, but does not provide PoC, exploit code, or patch details.

    11010782
    21.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27495: Breaking Out of the Box: n8n JavaScript Sandbox Escape (CVE-2026-27495) A critical sandbox escape vulnerability in the n8n workflow automation platform allowing authenticated users to execute arbitrary code on the host server. The flaw... https://cvereports.com/reports/CVE-2026-27495

    Post summary

    The post announces a critical sandbox escape vulnerability in n8n that lets authenticated users run arbitrary code on the host, but provides no PoC, exploit, or patch details.

    2000048
    32 followersView on X
  • Captain Kirk@captainkirk_15
    General

    Ruim honderdduizend n8n-servers missen update voor kritiek beveiligingslek; https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on

    Post summary

    The post highlights that over 100,000 n8n servers are missing an update for CVE‑2026‑27495, but it provides no detailed vulnerability information, PoC, exploit, or patch guidance.

    00000115
    152 followersView on X
  • Tech Nexus@ith_tokyo
    General

    毎週緊急レベルの脆弱性が報告されるn8nですが、数週間経っても改善されないのは基本設計の失敗や、セキュリティ標準の欠如が根本にあると思います。 https://www.cve.org/CVERecord?id=CVE-2026-27495

    Post summary

    The post comments that n8n's frequent emergency‑level vulnerabilities are not being promptly fixed due to design and standards issues, but it provides no technical detail, PoC, exploit, or patch information.

    0000040
    50 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A sandbox escape vulnerability (CVE-2026-27495) affects n8n's JavaScript Task Runner, potentially allowing code execution. Patching is recommended for #n8n users. #SandboxEscape #infosec https://www.pulsepatch.io/posts/cve-2026-27495-n8n-sandbox-escape

    Post summary

    A sandbox escape vulnerability (CVE-2026-27495) in n8n’s JavaScript Task Runner is disclosed, with the text recommending a patch for affected users.

    0000047
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-27495 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows… https://www.cve.org/CVERecord?id=CVE-2026-27495 ----- Traducción: CVE-2026-27495 n8n… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27495 affecting n8n, noting that versions prior to 2.10.1, 2.9.3, and 1.123.22 are vulnerable and that updates patch the issue.

    0000034
    54 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27495 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows… https://www.cve.org/CVERecord?id=CVE-2026-27495

    Post summary

    The CVE-2026-27495 vulnerability in n8n affects versions prior to 2.10.1, 2.9.3, and 1.123.22; upgrading to these versions mitigates the issue.

    00000375
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more