ADVISORY UNAUTH-2026-0033
TYPE cve
PRODUCT n8n
SEVERITY CRITICAL
n8n CVE-2026-21858 (Ni8mare)
published 2026-08-05 · updated 2026-08-05
Why it matters
Unauthenticated file access via improper webhook/form request parsing (Content-Type confusion). A vulnerable form-based workflow lets an unauthenticated attacker read arbitrary files (credentials, OAuth tokens) and can cascade to full instance takeover / RCE. CVSS 10.0.
Affected versions
- >=1.65.0,<1.121.0
Fixed in: 1.121.0
Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29.
Fix it
References
Cite this record
unauth.dev advisory UNAUTH-2026-0033 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0033. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.