SQL Injection Vulnerability in n8n by n8n.io
CVE-2026-103253

7HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103253?

The n8n automation platform is impacted by an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. This flaw allows attackers to manipulate input fields, specifically table or schema fields, by injecting single quotes. By doing so, they can append arbitrary SQL statements which can lead to the execution of Data Definition Language (DDL) or Data Manipulation Language (DML) commands with the privileges of the connected database credentials, potentially compromising sensitive data and system integrity.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mtholmquist
.