
Ni8mare: Critical n8n vulnerability puts self-hosted instances at risk
A new maximum-severity vulnerability has been discovered in the workflow automation platform n8n. Tracked as CVE-2026-21858 and known as Ni8mare, the flaw allows unauthenticated attackers to fully hijack vulnerable self-hosted n8n instances. The impact of this vulnerability is significant. n8n is frequently used to store API keys, access tokens, and other secrets, while coordinating …









/-3.5042587517567103,%2054.70635734010168,15.5/300X450@2X?access_token=pk.eyJ1Ijoid29tYmF0Y2hyaXMiLCJhIjoiY2pqaGEyd2lzMDQ3ZDN2bWQ4OTBsa2pmayJ9.ksVq6arM13qYhr76pco33w)