CVE-2026-44789Disclosure(n8n / n8n)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 9 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-18); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-05-14: 1Mentions · 2026-05-17: 1Mentions · 2026-05-18: 3Mentions · 2026-05-19: 1Mentions · 2026-05-20: 3Mentions · 2026-05-22: 1Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 3Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 2Technical Details · 2026-05-22: 105-1405-1705-1805-1905-2005-22
Signal classification2 categories
Disclosure
990.0%
Patch
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-171
Patch1
2026-05-183
Disclosure3
2026-05-191
Disclosure1
2026-05-203
Disclosure3
2026-05-221
Disclosure1
Full discourse10 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-44789, CVE-2026-44790 & CVE-2026-44791: 3 new vulnerabilities in n8n, 9.4 rating 🔥 Recently disclosed vulnerabilities in n8n allow an attacker to read arbitrary files from the server, achieve global prototype pollution and bypass the patch for previous vulnerability (CVE-2026-42232). 👉 https://nt.ls/dRB5p

    Post summary

    Three new vulnerabilities (CVE‑2026‑44789/44790/44791) have been disclosed in n8n, allowing attackers to read arbitrary files, perform global prototype pollution, and bypass a previous patch for CVE‑2026‑42232.

    217055225.7K
    7.6K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    n8nにCVSSスコア9.4の重大(Critical)な脆弱性が3件。CVE-2026-44790、CVE-2026-44791、CVE-2026-44789。ワークフローの作成/変更が可能なユーザがインフラ側で任意のコードを実行できる。修正版提供あり。 https://securityonline.info/n8n-automation-nodes-vulnerabilities-cve-2026-44791-rce/

    Post summary

    Three critical CVEs in n8n (CVE-2026-44790, 44791, 44789) allow users who can create or modify workflows to execute arbitrary code; a patch is available.

    020721.3K
    7.6K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na sérii zranitelností v platformě n8n, CVE-2026-44789, CVE-2026-44790 a CVE-2026-44791. Byly identifikovány tři kritické chyby v nativních uzlech HTTP Request, Git a XML, které umožňují nízko-privilegovaným autentizovaným útočníkům s oprávněním vytvářet nebo upravovat workflow dosáhnout vzdáleného spuštění kódu (RCE), číst libovolné soubory a v kombinaci zcela kompromitovat server. CVE-2026-44789 zneužívá prototype pollution v HTTP Request Node k dosažení RCE, CVE-2026-44790 umožňuje v Git Node libovolné čtení souborů a CVE-2026-44791 obchází opravy v XML Node a opět vede k RCE; všechny tři zranitelnosti mají CVSS skóre 9,4 a lze je řetězit k úplnému převzetí serveru, což výrazně zvyšuje riziko zejména ve sdílených a multi‑user automatizačních prostředích. Zneužití vyžaduje pouze autentizovaný přístup s nízkými oprávněními, nikoli administrátorská práva. Opravené verze jsou 1.123.43 a novější, 2.20.7 a novější nebo 2.22.1 a novější, a do dokončení nápravy se doporučuje omezit oprávnění k úpravám workflow. 📌 Doporučujeme aktualizovat na nejnovější verzi.

    Post summary

    Three critical RCE vulnerabilities in n8n (CVE‑2026‑44789‑44791) have been disclosed, with CVSS scores of 9.4, and users are advised to upgrade to patched versions (1.123.43+, 2.20.7+, or 2.22.1+) or restrict workflow permissions.

    02070681
    4.2K followersView on X
  • Tre B@trerbbb
    Disclosure

    github CVE-2026-44789: RCE. cloud misconfigs scale your blast radius by every region you operate in. audit IAM first. #GitHub #RCE #CVE-2026-44789 https://valtikstudios.com

    Post summary

    The post announces GitHub CVE‑2026‑44789 as a remote code execution vulnerability, noting that cloud misconfigurations could widen its impact, but offers no detailed technical or mitigation information.

    02020119
    17 followersView on X
  • TodayInCyber@TodayInCyberIO
    Disclosure

    4/5 n8n: five critical vulnerabilities tied to prototype pollution and code execution (CVE-2026-42231, CVE-2026-42232, CVE-2026-44789, CVE-2026-44790, CVE-2026-44791).

    Post summary

    The text announces five critical vulnerabilities in n8n, identifying them as prototype pollution and code execution issues, but provides no further details on PoC, exploits, patches, or active exploitation.

    100104
    8 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - n8n Multiple Critical Vulnerabilities (CVE-2026-44791, CVE-2026-44792, CVE-2026-45732, CVE-2026-44789, CVE-2026-44790) Multiple high-severity vulnerabilities were disclosed in n8n, including Prototype Pollution leading to RCE (via XML Node and HTTP Request Node), Arbitrary File Read via Git Node (CLI argument injection), Source Control Pull SQL Injection (PostgreSQL), Cross-user OAuth Credential Takeover, and Credential Exfiltration via SSRF Bypass. These issues can allow remote code execution, unauthorized data access, and credential theft depending on the configuration. 👉Affected: n8n < 1.123.43 | < 2.22.1 | < 2.20.7

    Post summary

    The tweet announces multiple high‑severity vulnerabilities in n8n, detailing the attack vectors (Prototype Pollution, RCE, file read, SQLi, OAuth takeover, SSRF) and the affected versions.

    00020109
    255 followersView on X
  • Hephaestvs@Vulcanux_
    Disclosure

    csirt_it: #Rilevata vulnerabilità critica n8n CVE-2026-44789 con gravità “alta” Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/rilevata-vulnerabilita-critica-n8n 🔄Aggiornamenti disponibili🔄 https://t.co/IJXGwohomE

    Post summary

    The post announces a critical RCE vulnerability (CVE‑2026‑44789) in n8n and notes that updates are available to address it.

    0001078
    613 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    n8n の深刻な脆弱性 CVE-2026-44789/44790/44791 が FIX:連鎖による RCE の可能性 https://iototsecnews.jp/2026/05/18/n8n-security-flaws-could-let-attackers-achieve-remote-code-execution/ ワークフロー自動化ツール n8n で発見された、複数の深刻な脆弱性を解説する記事です。問題の原因は、HTTP リクエストや Git/XML を処理する各機能において、入力データの検証や命令の組み立て方の不備にあります。具体的には、CVE-2026-44789 などの欠陥が存在し、低権限の認証ユーザーであっても、内部のデータ構造の書き換えが可能になるプロトタイプ汚染や、引数インジェクションによるコマンドの不正実行が可能になります。これらが連鎖すると、リモートコード実行 (RCE) に繋がり、最終的にはサーバの乗っ取りに至る恐れがあります。ご利用のチームは、ご注意ください。 #CVE202644789 #CVE202644790 #CVE202644791 #n8n #Vulnerability

    Post summary

    The text discloses serious prototype pollution and injection flaws in n8n that could lead to remote code execution, but it contains no PoC, exploit code, or patch information.

    00000110
    491 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    n8nに重大な脆弱性(CVE-2026-44789・CVE-2026-44790・CVE-2026-44791) https://rocket-boys.co.jp/security-measures-lab/cve-2026-44789-n8n-critical-vulnerabilities/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces critical CVEs in n8n and links to an advisory, without providing exploitation details or mitigation information.

    00000131
    407 followersView on X
  • Securelens@securelens
    Patch

    n8n patched a critical prototype pollution bug (CVE-2026-44789) in the HTTP Request node that an authenticated user could chain into RCE on the instance. patch to 1.123.43 or 2.22.1. https://github.com/advisories/GHSA-c8xv-5998-g76h

    Post summary

    n8n released specific patch versions (1.123.43/2.22.1) to address a critical prototype pollution CVE that could be exploited for RCE, with an advisory link provided.

    0000019
    8 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more