CVE-2026-42227Disclosure(n8n / n8n)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projects they are not a member of by supplying an arbitrary projectId query parameter to the public API variables endpoint. The handler queried the variables repository directly without enforcing project membership checks, bypassing the authorization-aware service layer used by the internal enterprise controller. If variables were misused to store sensitive information such as credentials or tokens, they should be rotated immediately. This issue only affects licensed enterprise or team deployments with multiple projects and the variables feature enabled. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 105-0405-05
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1General1
2026-05-051
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-42227 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list… https://www.cve.org/CVERecord?id=CVE-2026-42227

    Post summary

    The text references CVE‑2026‑42227 for n8n, noting that versions before 1.123.32, 2.17.4, and 2.18.1 allow authenticated users with a scoped API key to perform an action on variable:list, but it does not provide an exploit, PoC, or patch details.

    00010167
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42227 Unauthorized Variable Access in n8n Prior to Versions 1.123.32, 2.17.4, 2.18.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42227

    Post summary

    The text announces CVE‑2026‑42227 as an unauthorized variable access flaw in n8n affecting certain pre‑release versions, without evidence of a PoC, exploit, or active usage.

    0000045
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42227 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list… https://www.cve.org/CVERecord?id=CVE-2026-42227 ----- Traducción: CVE-2026-42227 n8n… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-42227 for n8n affecting older versions, but it lacks PoC, exploit details, active exploitation claims, patches, or in-depth technical info.

    0000031
    75 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.18.0node.js-

Explore more