VulnerabilitiesMar 11, 2026
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Two critical vulnerabilities were patched in the n8n workflow automation platform, including a sandbox escape (CVE-2026-27577) and an unauthenticated flaw (CVE-2026-27493) that both enable remote code execution. Both vulnerabilities carry CVSS scores above 9.4, posing severe risks to affected deployments.
Summary
Two critical vulnerabilities were patched in the n8n workflow automation platform, including a sandbox escape (CVE-2026-27577) and an unauthenticated flaw (CVE-2026-27493) that both enable remote code execution. Both vulnerabilities carry CVSS scores above 9.4, posing severe risks to affected deployments.
Indicators of Compromise
- cve — CVE-2026-27577
- cve — CVE-2026-27493