CVE-2026-42236Disclosure(n8n / n8n)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory resources by sending large registration payloads, rendering the n8n instance unavailable. The MCP enable/disable toggle gates MCP access but did not restrict client registrations, meaning the endpoint is reachable regardless of whether MCP access is enabled on the instance. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-06); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 1Technical Details · 2026-08-14: 105-0405-0505-0605-0708-14
Signal classification1 categories
Disclosure
6100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-051
Disclosure1
2026-05-062
Disclosure2
2026-05-071
Disclosure1
2026-08-141
Disclosure1
Full discourse6 posts
  • 陽向|中小企業の「人手不足×サイバーリスク」をn8nで解決する自動化エンジニア@n8nFlowMaster
    Disclosure

    n8nのMCP機能、「オフにした」つもりの設定は、実は入り口をふさいでいませんでした。 CVE-2026-42236(通称OverDoS)。MCPのOAuth登録窓口が未認証のまま残り、大量データを送るとDBを圧迫できます。対象は1.123.32/2.17.4/2.18.1未満。 ①自分のバージョンを確認 ②MCPを無効化していても窓口が生きていないか確認 ③外部から到達できる範囲を洗い出す うちはMCP機能自体を使っていません。それでも窓口が閉じているかは、実機でまだ確認できていません。

    Post summary

    The post identifies an unauthenticated OAuth endpoint in n8n’s MCP feature that could lead to database overload, offers mitigation steps, but does not discuss code, active exploitation, or a patch.

    0011091
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42236 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticate… https://www.cve.org/CVERecord?id=CVE-2026-42236

    Post summary

    The text announces CVE-2026-42236, briefly describing an unauthenticated access issue in n8n’s MCP OAuth registration endpoint, but provides no PoC, exploit, or mitigation details.

    00010148
    57.4K followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-42236: n8n MCP Flaw Allows Unauthenticated DoS Attack https://thecybrdef.com/cve-2026-42236-n8n-mcp-unauthenticated-dos-vulnerability/ #CVE202642236 #Cyberupdatenews #Cybersecurity

    Post summary

    The post announces CVE‑2026‑42236, a DoS vulnerability in n8n MCP that permits unauthenticated attacks, but offers no patches, PoC, or evidence of active exploitation.

    0000042
    2 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-42236: n8n MCP Flaw Allows Unauthenticated DoS Attack https://thecybrdef.com/cve-2026-42236-n8n-mcp-unauthenticated-dos-vulnerability/ #CVE202642236 #Cyberupdatenews #Cybersecurity

    Post summary

    The post announces CVE-2026-42236, a flaw in n8n's MCP that permits unauthenticated DoS attacks, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    5 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-42236: n8n MCP Flaw Allows Unauthenticated DoS Attack https://thecybrdef.com/cve-2026-42236-n8n-mcp-unauthenticated-dos-vulnerability/ #CVE202642236 #Cyberupdatenews #Cybersecurity

    Post summary

    The post announces the discovery of CVE-2026-42236, a flaw in n8n MCP that permits unauthenticated denial‑of‑service attacks.

    0000033
    9 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42236 Unauthenticated Denial of Service via MCP OAuth Client Registration in n8n https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42236

    Post summary

    A new unauthenticated Denial of Service vulnerability (CVE-2026-42236) in n8n's MCP OAuth client registration has been disclosed, with no PoC, exploit, or patch information provided.

    0000043
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.18.0node.js-

Explore more