New! Try the FREE Predictive Security Plugin for WordPress – Scan, Secure & Stay Safe in Seconds!

Current CyberSecurity Advisories

Critical Unauthenticated Remote Code Execution vulnerability in n8n workflow automation platform

Release date
08 January 2026
Alert rating
Critical

Description

A critical unauthenticated Remote Code Execution (RCE) vulnerability affecting n8n workflow automation platform has been observed. The critical vulnerability, tracked as CVE-2026-21858, allows unauthenticated threat actors to access sensitive files on the underlying server through execution of certain form-based workflows leading to RCE. This vulnerability is assessed as CVSS 10.0.

Audience

Small & medium businessesOrganisations & Critical InfrastructureGovernment

Current update

This document has been written for the IT teams of organisations and government.

Background

A critical unauthenticated Remote Code Execution (RCE) vulnerability, tracked as CVE2026-21858, has been observed affecting n8n workflow automation platform. The affected version includes 1.65.0 and previous versions.

This vulnerability can be exploited remotely allowing a threat actor to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant privileged access to an unauthenticated remote attacker. The vulnerability enables escalation from arbitrary file read to full RCE in n8n.

Mitigation advice

ASD’s ACSC advises organisations to follow mitigation advice provided by the n8n – Security Advisory in relation to this vulnerability.

Organisations should upgrade to version 1.121.0 or later to remediate the vulnerability.

Users are also recommended to critically assess the need for these instances to be internet facing and to not expose n8n to the internet unless necessary.

It is further recommended to require authentication for all Forms.

A potential temporary mitigation users may apply is to restrict or disable publicly accessible webhook and form endpoints until upgrading.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371).

Protect your assets with Predictive

TisaAssist bot
🤖 Hello, how can I assist you today?
I can help you with:
✅ Answer questions related to the website.
✅ Help you understand things you don't know.
❓ What's Tisalabs
💻 What's IoT
🔒 Why sensor data must be protected?