Path Injection Vulnerability in n8n Workflow Automation Platform
CVE-2026-86079

6.3MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86079?

The n8n workflow automation platform experienced a vulnerability where Elasticsearch and ElasticSecurity nodes improperly handled workflow-controlled index and document identifiers in REST request paths. This flaw allows malicious input containing path separators or dot segments to potentially redirect queries to unauthorized indices or cluster management endpoints, exploiting the security of stored Elasticsearch credentials. The issue has been resolved in n8n versions 1.123.76, 2.37.7, and 2.38.2, which implement proper encoding in request paths to mitigate these risks.

Affected Version(s)

n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2

n8n >= 2.0.0, < 2.37.7 < 2.0.0, 2.37.7

n8n < 1.123.76 < 1.123.76

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.