CVE-2026-33696Disclosure(n8n / n8n)

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch n8n n8n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. By supplying a crafted parameters as part of node configuration, an attacker could write attacker-controlled values onto `Object.prototype`. An attacker could use this prototype pollution to achieve remote code execution on the n8n instance. The issue has been fixed in n8n versions 2.14.1, 2.13.3, and 1.123.27. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only, and/or disable the XML node by adding `n8n-nodes-base.xml` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-03-25); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 6d
01223Mentions · 2026-03-25: 3Mentions · 2026-03-27: 2Mentions · 2026-08-16: 3Mentions · 2026-08-17: 1Mentions · 2026-09-08: 1Mentions · 2026-09-29: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-08-16: 2PoC Mentioned / Linked · 2026-09-08: 1Exploit Tool / Code · 2026-08-17: 1Active Exploitation · 2026-08-17: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-25: 3Technical Details · 2026-03-27: 2Technical Details · 2026-08-16: 3Technical Details · 2026-09-08: 103-2503-2708-1608-1709-0809-29
Signal classification5 categories
Disclosure
330.0%
PoC
330.0%
Patch
220.0%
Exploit
110.0%
Active Exploitation
110.0%
Referenced assets39 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-253
Disclosure2Patch1
2026-03-272
Disclosure1Patch1
2026-08-163
Exploit1PoC2
2026-08-171
Active Exploitation1
2026-09-081
PoC1
Full discourse11 posts
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce

    Post summary

    The text announces CVE‑2026‑33696 as an RCE in n8n, providing a link to a writeup that likely contains a proof‑of‑concept.

    111054228.0K
    162.1K followersView on X
  • /r/netsec@_r_netsec
    PoC

    CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce

    Post summary

    A link is provided to a writeup describing an RCE vulnerability in n8n, indicating a proof‑of‑concept exists but offering no evidence of active exploitation, patches, or false positive status.

    080751.3K
    34.1K followersView on X
  • /r/netsec@_r_netsec

    CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce

    050641.1K
    34.1K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・SAP Commerce Cloudの脆弱性が悪用される(CVE-2026-58231) https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html ・GeoServerの未修正ゼロデイが悪用される https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/ ・macOSの画面共有における脆弱性、モネロマイナーの展開に悪用される(CVE-2026-65400) https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/ ・SAP Commerce Cloudの脆弱性、パッチ適用から数日で悪用される(CVE-2026-58231) https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html <マルウェア・その他脅威> ・macOS狙う新種のマルウェアAmnesiaStealer、リモート操作でブラウザを乗っ取るhttps://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/ ・Appleが110か国のユーザーに警告 個人を狙う傭兵型スパイウェアの標的になった恐れ https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html ・脅威アクターMustang Panda、CoolClientマルウェアにカーネルルートキットを追加 https://securityaffairs.com/197274/apt/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html ・大規模なDDoS攻撃により暗号化メッセージサービスThreemaが一時停止 https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/ <ランサムウェア> ・シェル社、Cl0pによるデータ侵害主張に関するインシデントを調査中 https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/ <データ侵害/サイバー犯罪> ・仏税務当局が高度なサイバー攻撃受け、納税者67万8千人分のデータが流出 https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html ・ハードウェアウォレットTrezor、配送業者ShipMonkのデータ侵害で顧客1万4千人に影響 https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/ ・英企業BeaconのCRMで発生したデータ侵害、1,000超の慈善団体に影響 https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/ ・ポーランドの大手電子カルテシステムMyDrから患者データ1,800万人分が盗まれたか https://badcyber.com/hackers-claim-to-have-stolen-the-data-of-more-than-18-million-poles-from-mydr/ ・企業向けコミュニケーションプラットフォームRingCentral、データ侵害受け160万人に影響か https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/ ・2,500以上の組織が影響受けた攻撃、LiteLLMではなくTrivyの侵害が原因か https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/ <AI関連> ・AIプラットフォームのアカウントにおけるハッキングの有無を見分ける方法 https://techcrunch.com/2026/08/15/how-to-tell-if-your-ai-platforms-accounts-have-been-hacked/ ・アンソロピックがClaudeのAI生成テキストにウォーターマークを導入へ その方法とは https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/ ・米裁判所のAI使用を疑い、原告が訴訟に勝つため書類にプロンプトを挿入 https://arstechnica.com/tech-policy/2026/08/suspecting-court-of-using-ai-man-injected-prompts-in-filings-to-try-to-win-case/ ・自律型AIによる攻撃、重要インフラに「明白かつ差し迫った危険」をもたらす https://www.theregister.com/security/2026/08/14/autonomous-ai-attacks-pose-clear-and-present-danger-to-critical-infrastructure/5287594 <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・欧州・ブラジルでインターネットバンキングのハッキング容疑者を複数逮捕 https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil ・パキスタンでベトナム人・中国人の詐欺師258名を逮捕 氏名とパスポート情報も公開 https://ministryofcyberaffairs.com/news/pakistan-arrests-258-vietnamese-chinese-scammers-in-islamabad-for-running-transnational-scam-operations-6039eb03-cf86-4750-92e8-8eebf6acc100 ・OpenAI、ゴールドマン・サックス社員の犯罪計画に関するChatGPTの履歴をFBIに通報 https://futurism.com/artificial-intelligence/openai-reports-goldman-sachs-analyst-fbi-horrifying-chatgpt-conversations <リサーチ/攻撃手法/TTP> ・公開されている証明書ログから社内アプリを特定する https://naveensrinivasan.com/posts/2026-08-07-finding-hidden-internal-apps-through-public-certificate-logs/ ・n8nで特定のschemaNameからリモートコード実行を実践する方法(CVE-2026-33696) https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce ・LiteLLMサプライチェーン攻撃 — TeamPCPグループ使用の「SANDCLOCK」をTrivy GitHub Actionに仕込み、CI/CD環境から認証情報盗むキャンペーン https://www.resecurity.com/blog/article/the-litellm-supply-chain-attack-teampcp-sandclock-cicd-credential-harvesting-campaign-via-a-backdoored-trivy-github-action ・Cookie窃取が再び可能に https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/ ・Google SheetsをC2サーバーにしたPATCHCORDのスパイ活動、APT36が関与か https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html ・新たなLinuxボットネットEvooo1Bot、ルーターを通信中継ノードに https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/ ・Chrome DevToolsの悪用でWindowsの起動中ブラウザから認証済みセッションが乗っ取り可能に https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html <その他> ・Namecheapの大規模障害について https://jestr.ai/blog/namecheap-meltdown ・米司法当局、2029年から盗聴におけるハッキングツールの使用状況を公表へ https://www.scworld.com/brief/u-s-judiciary-to-publicly-disclose-use-of-hacking-tools-in-wiretaps-starting-2029 ・Google Cloud、2029年に移行完了を目標としたポスト量子暗号ロードマップを発表 https://www.securityweek.com/google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal/ ・米司法当局、政府のスパイウェア使用頻度を公表へ https://techcrunch.com/2026/08/14/us-courts-will-start-publishing-how-often-the-government-uses-spyware/

    Post summary

    The text reports that CVE‑2026‑58231 and CVE‑2026‑65400 are actively being exploited, and a writeup demonstrates code to exploit CVE‑2026‑33696. No PoC or patch details are provided.

    100212.4K
    1.3K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerabilities identified in #n8n. #CVE-2026-33696 #CVE-2026-33660 #CVE-2026-33713. These #RCE and #SQLi flaws allow for complete system compromise. #Patch #Patch #Patch More info: https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-n8n-patch-immediately

    Post summary

    This advisory alerts users to critical RCE and SQLi flaws in n8n (CVE‑2026‑33696, CVE‑2026‑33660, CVE‑2026‑33713) and urges immediate patching, citing a specific official advisory.

    00001199
    7.2K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33696 n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflow… https://www.cve.org/CVERecord?id=CVE-2026-33696

    Post summary

    CVE-2026-33696 is an authenticated workflow modification vulnerability in n8n, mitigated by upgrading to versions 2.14.1, 2.13.3, or 1.123.27.

    10000130
    56.8K followersView on X
  • Komodo Cyber Security@Komodosec
    PoC

    CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet references CVE‑2026‑33696 and links to a write‑up that likely includes a proof‑of‑concept for an RCE in n8n. No patch, active exploitation, or debunking is mentioned.

    0000053
    1.5K followersView on X
  • Valvet Online@VALVETONLINE
    Exploit

    N8N RCE: ONE REQUEST, FULL SHELL 1. CVE-2026-33696, CVSS 9.4. A __proto__ schema name pollutes Object.prototype 2. Chained to the Git node, one webhook request gives you a shell #n8n #CyberSecurity #RCE https://t.co/yd3Se7T6hA

    Post summary

    CVE-2026-33696 in n8n enables a single webhook request to gain a full shell through prototype‑pollution, highlighting a severe RCE risk.

    0000048
    59 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 CVE-2026-33696、Critical severity n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE https://github.com/advisories/GHSA-mxrg-77hm-89hv

    Post summary

    The text announces a critical vulnerability (CVE-2026-33696) in n8n involving prototype pollution that enables remote code execution, but provides no PoC, exploitation evidence, or patch information.

    00000389
    6.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33696 - n8n Vulnerable to Prototype Pollution in XML & GSuiteAdmin node parameters lead to RCE Intel Report: https://ift.tt/FPYoX4A

    Post summary

    A new CVE-2026-33696 affecting n8n’s XML and GSuiteAdmin node parameters via prototype pollution leading to RCE has been disclosed, with an Intel report linked.

    0000044
    286 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33696: n8n Vulnerable to Prototype Poll... Prototype pollution via XML/GSuiteAdmin nodes escalates to RCE with just workflow perms - Object.prototype poisoning = ... https://zerodaysignal.com/vulnerability/CVE-2026-33696 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-33696 describes a prototype‑pollution vulnerability in n8n’s XML/GSuiteAdmin nodes that can lead to remote code execution when a workflow has execute permissions, as detailed on zerodaysignal.com.

    0000069
    168 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.14.0node.js-

Explore more