CVE-2026-33751Disclosure(n8n / n8n)

LOWCVSS 4.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacharacters to pass through unescaped when user-controlled input was interpolated into LDAP search filters. In workflows where external user input is passed via expressions into the LDAP node's search parameters, an attacker could manipulate the constructed filter to retrieve unintended LDAP records or bypass authentication checks implemented in the workflow. Exploitation requires a specific workflow configuration. The LDAP node must be used with user-controlled input passed via expressions (e.g., from a form or webhook). The issue has been fixed in n8n versions 1.123.27, 2.13.3, and 2.14.1. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only, disable the LDAP node by adding `n8n-nodes-base.ldap` to the `NODES_EXCLUDE` environment variable, and/or avoid passing unvalidated external user input into LDAP node search parameters via expressions. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-25: 3Technical Details · 2026-03-25: 203-25
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33751 n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacha… https://www.cve.org/CVERecord?id=CVE-2026-33751

    Post summary

    The CVE-2026-33751 entry describes an LDAP filter escape logic flaw in n8n’s LDAP node that affects versions before 1.123.27, 2.13.3, and 2.14.1, but it provides no evidence of a PoC, exploit, active use, or patch details.

    10000130
    56.8K followersView on X
  • Selwyn Jayme | TeckGrowth@algonovalabs
    General

    @CVEnew CVE-2026-33751 highlights a security risk, but what about the manual effort to patch or monitor for similar flaws? Automating vulnerability scanning with n8n AI Agents can save 75% of administrative time.

    Post summary

    The tweet references CVE-2026-33751 as a security risk but provides no details on the vulnerability, exploitation, or patching efforts, instead discussing automation of vulnerability scanning to reduce manual work.

    0000035
    437 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33751 - n8n Vulnerable to LDAP Filter Injection in LDAP Node Intel Report: https://ift.tt/lixKuZm

    Post summary

    An alert announces CVE-2026-33751, an LDAP filter injection vulnerability in n8n's LDAP node, providing a link to an Intel report but no PoC, exploit, or patch details.

    0000021
    286 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.14.0node.js-

Explore more