CVE-2026-27497Patch(n8n / n8n)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch n8n n8n systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code and write arbitrary files on the n8n server. The issues have been fixed in n8n versions 2.10.1, 2.9.3, and 1.123.22. Users should upgrade to one of these versions or later to remediate all known vulnerabilities. If upgrading is not immediately possible, administrators should consider the following temporary mitigations. Limit workflow creation and editing permissions to fully trusted users only, and/or disable the Merge node by adding `n8n-nodes-base.merge` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 7 mentions (2026-02-26); latest day: 1
  • 10 total mentions across 3 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline10 mentions / 3d
02457Mentions · 2026-02-26: 7Mentions · 2026-02-27: 2Mentions · 2026-03-11: 1PoC Mentioned / Linked · 2026-02-27: 1Patch / Workaround · 2026-02-26: 4Patch / Workaround · 2026-02-27: 2Patch / Workaround · 2026-03-11: 1Technical Details · 2026-02-26: 7Technical Details · 2026-02-27: 2Technical Details · 2026-03-11: 102-2602-2703-11
Signal classification2 categories
Patch
770.0%
Disclosure
330.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-267
Disclosure3Patch4
2026-02-272
Patch2
2026-03-111
Patch1
Full discourse10 posts
  • Jintao Zhang 张晋涛@zhangjintao9020
    Patch

    最近 n8n 爆出来了 4 个高危漏洞 CVE-2026-27495/CVE-2026-27497/CVE-2026-27498/CVE-2026-27577 一个 9.0,三个 9.4。 基本的影响都是允许执行远程命令。 这个事情倒是也不能说完全怪 n8n,大多数这种场景下的工具都会有类似的情况,各种 sandbox 逃逸,大家如果有自己部署的 n8n 记得升级到最新版

    Post summary

    The post reports four high‑severity n8n vulnerabilities (CVE‑2026‑27495, ‑27497, ‑27498, ‑27577) that allow remote command execution, and urges users to update to the latest version.

    011724.9K
    12.5K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple Critical Vulnerabilities in #n8n. CVE-2026-27497 CVE-2026-27577 CVE-2026-27495 CVSS: 9.4. These vulnerabilities can lead to a full compromised host https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-n8n-patch-immediately #Patch #Patch #Patch

    Post summary

    Multiple critical CVEs (CVE‑2026‑27497, 27495, 27577) in n8n with CVSS 9.4 can fully compromise a host; users are urged to patch immediately.

    02210707
    7.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    n8n patches three critical 9.4 CVSS vulnerabilities (CVE-2026-27497, 27577, 27495) allowing remote code execution via Merge nodes and sandboxes. Update now! #n8n #CyberSecurity #RCE #Automation #InfoSec #Vulnerability #PatchAlert #AppSec #DevOps https://securityonline.info/automation-at-risk-triple-9-4-severity-rce-flaws-threaten-n8n-workflow-servers/

    Post summary

    n8n has released patches for three critical CVEs that enable remote code execution via Merge nodes and sandboxes; users are urged to update immediately.

    00021361
    10.4K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `n8n` is affected by a RCE vulnerability (CVE-2026-27497) via its Merge Node. Update to 1.123.22 to mitigate this #n8n #RCE #infosec issue. https://www.pulsepatch.io/posts/cve-2026-27497-n8n-remote-code-execution

    Post summary

    The post discloses an RCE vulnerability (CVE‑2026‑27497) in n8n’s Merge Node and advises upgrading to 1.123.22, providing a link to further details.

    0000053
    1 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code and write arbitrary files on the n8n server』 CVE-2026-27497 n8n has Potential Remote Code Execution via Merge Node https://github.com/advisories/GHSA-wxx7-mcgf-j869

    Post summary

    Authenticated users can exploit the Merge node’s SQL query mode in n8n to execute arbitrary code and write files, exposing a remote code execution vulnerability (CVE-2026-27497).

    00000431
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-27497 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows… https://www.cve.org/CVERecord?id=CVE-2026-27497 ----- Traducción: CVE-2026-27497 n8n… http://infoflow.cloud`

    Post summary

    CVE-2026-27497 affects n8n, allowing authenticated users to create or modify workflows before versions 2.10.1, 2.9.3, and 1.123.22; patches are available in those releases.

    0000031
    54 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27497 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows… https://www.cve.org/CVERecord?id=CVE-2026-27497

    Post summary

    The CVE-2026-27497 vulnerability in n8n affects versions prior to 2.10.1, 2.9.3, and 1.123.22, and patches are available in those newer releases.

    00000161
    56.6K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-27497 impacts n8n-io n8n. Authenticated users can inject code via Merge node, risking full server takeover. Upgrade to 2.10.1/2.9.3/1.123.22 ASAP! 🔒 https://radar.offseq.com/threat/cve-2026-27497-cwe-94-improper-control-of-generati-7583bd72 #OffSeq #n8n #C... https://t.co/9xJV8q0eRP

    Post summary

    The tweet alerts users to a critical code injection vulnerability in n8n-io n8n that allows authenticated users to execute code via the Merge node, and urges an immediate upgrade to specific patched versions.

    0000060
    270 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27497: SQLi-ception: Breaking n8n's Merge Node via AlaSQL RCE n8n, the popular workflow automation tool that connects everything to everything, recently discovered it had connected its internal server shell to authenticated users. CVE-2026-27... https://cvereports.com/reports/CVE-2026-27497

    Post summary

    A new SQL injection vulnerability (CVE-2026-27497) in n8n's Merge Node allows remote code execution via AlaSQL, as reported by the CVE report.

    0000061
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27497 Authenticated Code Execution via Merge Node SQL Query in n8n Work... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27497 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑27497, an authenticated code execution flaw in n8n via a Merge Node SQL query, linking to a vulnerability details page but providing no PoC, exploit, or patch information.

    0000044
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more