CVE-2026-44791Patch(n8n / n8n)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the n8n host. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-05-18); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-05-18: 3Mentions · 2026-05-19: 1Mentions · 2026-05-20: 3Mentions · 2026-06-11: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-18: 3Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 205-1405-1505-1805-1905-2006-11
Signal classification3 categories
Patch
550.0%
Disclosure
440.0%
General
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-151
Patch1
2026-05-183
Disclosure1Patch2
2026-05-191
Patch1
2026-05-203
Disclosure2Patch1
2026-06-111
General1
Full discourse10 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-44789, CVE-2026-44790 & CVE-2026-44791: 3 new vulnerabilities in n8n, 9.4 rating 🔥 Recently disclosed vulnerabilities in n8n allow an attacker to read arbitrary files from the server, achieve global prototype pollution and bypass the patch for previous vulnerability (CVE-2026-42232). 👉 https://nt.ls/dRB5p

    Post summary

    Three newly disclosed n8n vulnerabilities (CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) enable arbitrary file reads, global prototype pollution, and patch bypass, but no PoC, exploit code, or active exploitation is referenced.

    217055225.7K
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    n8n fixes three critical 9.4 CVSS flaws (CVE-2026-44790/91/89). Authenticated users can break sandboxes for local file read and server-level RCE. Patch now! #n8n #WorkflowAutomation #CyberSecurity #InfoSec #RCE #Vulnerability #DevOps #PrototypePollution https://securityonline.info/n8n-automation-nodes-vulnerabilities-cve-2026-44791-rce/ https://t.co/E2EKNzp94P

    Post summary

    n8n has released a patch for three critical CVEs (CVE‑2026‑44790/91/89) that permitted authenticated users to perform local file reads and server‑level RCE; the update is now available.

    18039133.9K
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    n8nにCVSSスコア9.4の重大(Critical)な脆弱性が3件。CVE-2026-44790、CVE-2026-44791、CVE-2026-44789。ワークフローの作成/変更が可能なユーザがインフラ側で任意のコードを実行できる。修正版提供あり。 https://securityonline.info/n8n-automation-nodes-vulnerabilities-cve-2026-44791-rce/

    Post summary

    Three critical CVEs (CVE-2026-44789/44790/44791) affecting n8n allow users with workflow creation/modification rights to execute arbitrary code; a patch has been released.

    020721.3K
    7.6K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na sérii zranitelností v platformě n8n, CVE-2026-44789, CVE-2026-44790 a CVE-2026-44791. Byly identifikovány tři kritické chyby v nativních uzlech HTTP Request, Git a XML, které umožňují nízko-privilegovaným autentizovaným útočníkům s oprávněním vytvářet nebo upravovat workflow dosáhnout vzdáleného spuštění kódu (RCE), číst libovolné soubory a v kombinaci zcela kompromitovat server. CVE-2026-44789 zneužívá prototype pollution v HTTP Request Node k dosažení RCE, CVE-2026-44790 umožňuje v Git Node libovolné čtení souborů a CVE-2026-44791 obchází opravy v XML Node a opět vede k RCE; všechny tři zranitelnosti mají CVSS skóre 9,4 a lze je řetězit k úplnému převzetí serveru, což výrazně zvyšuje riziko zejména ve sdílených a multi‑user automatizačních prostředích. Zneužití vyžaduje pouze autentizovaný přístup s nízkými oprávněními, nikoli administrátorská práva. Opravené verze jsou 1.123.43 a novější, 2.20.7 a novější nebo 2.22.1 a novější, a do dokončení nápravy se doporučuje omezit oprávnění k úpravám workflow. 📌 Doporučujeme aktualizovat na nejnovější verzi.

    Post summary

    Three critical RCE vulnerabilities in n8n with CVSS 9.4 are disclosed, and the advisory recommends updating to patched releases and limiting workflow edit permissions.

    02070681
    4.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    📍 CVE-2026-44791 هذه Patch Bypass للثغرة السابقة في XML Node. يعني التحديث الأول أغلق طريقه استغلال، لكن تسبب في مشكله ثانيه ( حركات مايكروسفت ) المهاجم يحتاج نفس الشرط: حساب عنده صلاحية إنشاء أو تعديل workflows. وعند دمجها مع Nodes ثانية، قد تؤدي إلى RCE على سيرفر n8n.

    Post summary

    The post notes a patch bypass for CVE‑2026‑44791, indicating the first patch closed the exploit path but introduced a new issue, and that the vulnerability still allows RCE when privileged workflow accounts are combined with other nodes.

    10010274
    49.3K followersView on X
  • TodayInCyber@TodayInCyberIO
    Disclosure

    4/5 n8n: five critical vulnerabilities tied to prototype pollution and code execution (CVE-2026-42231, CVE-2026-42232, CVE-2026-44789, CVE-2026-44790, CVE-2026-44791).

    Post summary

    The tweet announces the discovery of five critical prototype‑pollution and code‑execution vulnerabilities in n8n (CVE‑2026‑42231, CVE‑2026‑42232, CVE‑2026‑44789, CVE‑2026‑44790, CVE‑2026‑44791) with no exploit or patch details provided.

    100104
    8 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - n8n Multiple Critical Vulnerabilities (CVE-2026-44791, CVE-2026-44792, CVE-2026-45732, CVE-2026-44789, CVE-2026-44790) Multiple high-severity vulnerabilities were disclosed in n8n, including Prototype Pollution leading to RCE (via XML Node and HTTP Request Node), Arbitrary File Read via Git Node (CLI argument injection), Source Control Pull SQL Injection (PostgreSQL), Cross-user OAuth Credential Takeover, and Credential Exfiltration via SSRF Bypass. These issues can allow remote code execution, unauthorized data access, and credential theft depending on the configuration. 👉Affected: n8n < 1.123.43 | < 2.22.1 | < 2.20.7

    Post summary

    High‑severity n8n vulnerabilities have been disclosed, including Prototype Pollution leading to remote code execution, arbitrary file read, SQL injection, OAuth credential takeover, and SSRF bypass, impacting all n8n versions below 1.123.43, 2.22.1, and 2.20.7.

    00020109
    255 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44791: n8n XML Node Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04l272c0

    Post summary

    The provided snippet only lists the CVE and a link to additional content, offering no explicit details, exploits, or mitigations.

    0000030
    31 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    n8nに重大な脆弱性(CVE-2026-44789・CVE-2026-44790・CVE-2026-44791) https://rocket-boys.co.jp/security-measures-lab/cve-2026-44789-n8n-critical-vulnerabilities/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The text announces that n8n has three critical vulnerabilities (CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) and provides a link for further details.

    00000131
    407 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 『An authenticated user with permission to create or modify workflows could bypass the patch for GHSA-hqr4-h3xv-9m3r in the XML node.』 CVE-2026-44791 n8n Has an XML Node Prototype Pollution Patch Bypass https://github.com/advisories/GHSA-wrwr-h859-xh2r

    Post summary

    The advisory notes that an authenticated user can bypass the XML node prototype pollution patch in n8n, revealing a new vulnerability (CVE‑2026‑44791).

    00000431
    6.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more