CVE-2026-1470 is a critical Remote Code Execution (RCE) vulnerability affecting n8n, an open-source workflow automation platform. Authenticated users can exploit a flaw in the Expression evaluation system to execute arbitrary code with the privileges of the n8n process. This allows for full compromise of the instance, including data theft and system-level operations. With a CVSS score of 9.9 (CRITICAL), the vulnerability is easily exploitable over the network with low privileges and complexity. While not yet in CISA's KEV catalog, it has garnered significant community attention and media coverage, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.123.17CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
>= 2.0.0, < 2.4.5CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
2.5.0CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:2.5.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
n8n Remote Code Execution (CVE-2026-1470)
Mar 26, 2026n8n Remote Code Execution (CVE-2026-1470)
Mar 26, 2026n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
Jan 27, 2026