ADVISORY UNAUTH-2026-0002
TYPE exposure-class
PRODUCT n8n
SEVERITY CRITICAL
n8n instance open — settings or owner-setup reachable without login
published 2026-08-05 · updated 2026-08-05
Why it matters
If your n8n setup page or settings endpoint answers without a login, a stranger can claim the instance as owner or read its configuration — and n8n holds your API keys and workflow credentials. Gate 0 testing showed bots hunting for credential files on exposed n8n within about an hour of the port going online.
What a probe sees
GET :5678/rest/settings answers a JSON settings blob without login, or the owner-setup page is reachable.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
unclaimed-setup
In the wild
HONEYPOT EVIDENCE · only unauth.dev publishes this
SERVICE n8n
PROBES (30d) 431
FIRST SEEN 2026-07-28
LAST SEEN 2026-08-05
Day-granularity probe counts from the unauth.dev botwatch honeypot (431 observed across retained history), refreshed monthly. No source IPs exist in the underlying data. Live view: /botwatch.
Fix it
References
- https://docs.n8n.io/hosting/configuration/environment-variables/
- https://docs.n8n.io/hosting/securing/overview/
Cite this record
unauth.dev advisory UNAUTH-2026-0002 — observed 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0002. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.