CVE-2026-27498Disclosure(n8n / n8n)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch n8n n8n systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk node with git operations to achieve remote code execution. By writing to specific configuration files and then triggering a git operation, the attacker could execute arbitrary shell commands on the n8n host. The issue has been fixed in n8n versions 2.2.0 and 1.123.8. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations. Limit workflow creation and editing permissions to fully trusted users only, and/or disable the Read/Write Files from Disk node by adding `n8n-nodes-base.readWriteFile` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 7 mentions (2026-02-26); latest day: 1
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline11 mentions / 4d
02457Mentions · 2026-02-25: 2Mentions · 2026-02-26: 7Mentions · 2026-02-27: 1Mentions · 2026-03-11: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-26: 1Exploit Tool / Code · 2026-02-25: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 6Technical Details · 2026-02-27: 1Technical Details · 2026-03-11: 102-2502-2602-2703-11
Signal classification4 categories
Disclosure
654.5%
Patch
327.3%
PoC
19.1%
General
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure1PoC1
2026-02-267
Disclosure5General1Patch1
2026-02-271
Patch1
2026-03-111
Patch1
Full discourse11 posts
  • Fatih Çelik@fatihclk01
    Disclosure

    I've discovered another vulnerability causing RCE in n8n, tracked as CVE-2026-27498. I'm dropping the link to the blog post in the replies. It's a quick read this time.

    Post summary

    A new RCE vulnerability (CVE-2026-27498) in n8n has been discovered, and the author plans to share a blog post with details.

    32034163.4K
    469 followersView on X
  • Fatih Çelik@fatihclk01
    PoC

    https://fatihhcelik.github.io/posts/n8n-cve-2026-27498/

    Post summary

    The blog post discloses CVE-2026-27498 in n8n, provides PoC code and technical details, and references the vendor patch, but does not report active exploitation.

    020189924
    469 followersView on X
  • Jintao Zhang 张晋涛@zhangjintao9020
    Patch

    最近 n8n 爆出来了 4 个高危漏洞 CVE-2026-27495/CVE-2026-27497/CVE-2026-27498/CVE-2026-27577 一个 9.0,三个 9.4。 基本的影响都是允许执行远程命令。 这个事情倒是也不能说完全怪 n8n,大多数这种场景下的工具都会有类似的情况,各种 sandbox 逃逸,大家如果有自己部署的 n8n 记得升级到最新版

    Post summary

    The post announces four high‑severity CVEs affecting n8n (remote command execution) and urges users to upgrade to the latest version for remediation.

    011724.9K
    12.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27498 Authenticated Remote Code Execution in n8n Workflow Automation Platform https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27498

    Post summary

    A new authenticated remote code execution vulnerability (CVE-2026-27498) has been identified in the n8n Workflow Automation Platform.

    1000061
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Critical arbitrary command execution (CVE-2026-27498) impacts `n8n` via file write and Git operations. Update to 1.123.8 to mitigate risk. #n8n #RCE #InfoSec https://www.pulsepatch.io/posts/cve-2026-27498-n8n-arbitrary-command-execution

    Post summary

    CVE-2026-27498 allows arbitrary command execution in n8n through file write and Git operations; updating to version 1.123.8 mitigates the vulnerability.

    0000051
    1 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk node with git operations to achieve remote code execution.』 CVE-2026-27498 n8n has Arbitrary Command Execution via File Write and Git Operations https://github.com/advisories/GHSA-x2mw-7j39-93xq

    Post summary

    The advisory reveals that authenticated users in n8n can chain workflow nodes to perform arbitrary command execution via file write and git operations, enabling remote code execution.

    00000371
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27498 n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could cha… https://www.cve.org/CVERecord?id=CVE-2026-27498 ----- Traducción: CVE-2026-27498 n8n… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-27498, a vulnerability in n8n that allows authenticated users to modify workflows before certain versions, as documented in the CVE record.

    0000027
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27498 n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could cha… https://www.cve.org/CVERecord?id=CVE-2026-27498

    Post summary

    The CVE highlights a flaw in n8n where authenticated users with workflow creation/ modification rights can exploit a vulnerability in versions prior to 2.2.0 and 1.123.8.

    00000145
    56.6K followersView on X
  • Selwyn | Automating Solopreneur Workflows@algonovalabs
    General

    Vulnerabilities like CVE-2026-27498 highlight the need for robust security measures in automation tools. Implementing proactive monitoring and patching processes can prevent 'GitPwned' scenarios. Automating security updates can save hours of manual intervention and safeguard your workflows. Curious about smart automation solutions? Check my profile for insights.

    Post summary

    The post references CVE-2026-27498 but only offers general security recommendations, lacking specific vulnerability details or exploitation evidence.

    0000038
    211 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27498: n8n Automation RCE: When 'GitOps' Becomes 'GitPwned' A critical Remote Code Execution (RCE) vulnerability exists in n8n, the popular workflow automation tool. By design, n8n allows users to automate file operations. However, a failure ... https://cvereports.com/reports/CVE-2026-27498

    Post summary

    The text announces a critical RCE vulnerability in n8n, detailing its nature but providing no PoC, exploit, or mitigation information.

    0000048
    32 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL code injection alert in n8n-io n8n! Auth users can exploit to gain shell access on vulnerable hosts. Patch to 2.2.0 / 1.123.8 ASAP. Restrict permissions & disable risky nodes! https://radar.offseq.com/threat/cve-2026-27498-cwe-94-improper-control-of-generati-673d3ea... https://t.co/g8ex3nZcmK

    Post summary

    A critical code injection vulnerability (CVE‑2026‑27498) in n8n‑io n8n allows authenticated users to gain shell access; patching to 2.2.0 / 1.123.8 is urgently recommended.

    0000059
    270 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more