Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1470

47
FAUCET Score

CVE-2026-1470 is a critical Remote Code Execution (RCE) vulnerability affecting n8n, an open-source workflow automation platform. Authenticated users can exploit a flaw in the Expression evaluation system to execute arbitrary code with the privileges of the n8n process. This allows for full compromise of the instance, including data theft and system-level operations. With a CVSS score of 9.9 (CRITICAL), the vulnerability is easily exploitable over the network with low privileges and complexity. While not yet in CISA's KEV catalog, it has garnered significant community attention and media coverage, indicating a high potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.123.17CPE matchmatch criteria
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
>= 2.0.0, < 2.4.5CPE matchmatch criteria
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
2.5.0CPE matchmatch criteria
cpe:2.3:a:n8n:n8n:2.5.0:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
18.72%
Probability of exploitation in next 30 days
EPSS Percentile
97.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1872 is in the 96th percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: n8nFixed in: 1.123.17
npmpatch availablevia ghsa
Product: n8nFixed in: 2.4.5
npmpatch availablevia ghsa
Product: n8nFixed in: 2.5.1
3cxvendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted

Vendor Advisories (3)

inveniosoftwarellm-inveniosoftware-72e02fae9ffe2614CRITICAL

n8n Remote Code Execution (CVE-2026-1470)

Mar 26, 2026
3cxllm-3cx-9b138bac7f52e37aCRITICAL

n8n Remote Code Execution (CVE-2026-1470)

Mar 26, 2026
npmGHSA-5xrp-6693-jjx9critical

n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution

Jan 27, 2026

References

github.com / n8n-io/n8n/commit/aa4d1e5825829182afa0ad5b81f602638f55fa04
Patch
research.jfrog.com / vulnerabilities/n8n-expression-node-rce
ExploitPatchThird Party Advisory