← advisory ledger

ADVISORY UNAUTH-2026-0002
TYPE exposure-class
PRODUCT n8n
SEVERITY CRITICAL

CRITICAL

n8n instance open — settings or owner-setup reachable without login

published 2026-08-05 · updated 2026-08-05

Why it matters

If your n8n setup page or settings endpoint answers without a login, a stranger can claim the instance as owner or read its configuration — and n8n holds your API keys and workflow credentials. Gate 0 testing showed bots hunting for credential files on exposed n8n within about an hour of the port going online.

What a probe sees

GET :5678/rest/settings answers a JSON settings blob without login, or the owner-setup page is reachable.

Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).

unclaimed-setup

In the wild

HONEYPOT EVIDENCE · only unauth.dev publishes this
SERVICE n8n
PROBES (30d) 431
FIRST SEEN 2026-07-28
LAST SEEN 2026-08-05

Day-granularity probe counts from the unauth.dev botwatch honeypot (431 observed across retained history), refreshed monthly. No source IPs exist in the underlying data. Live view: /botwatch.

Fix it

Fix card: n8n-exposed →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0002 — observed 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0002. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.