Vulnerability Report

CVE-2026-1470

RCE

Title: RCE in n8n Workflow Expression Evaluation

Auth Bypass

Proof Of Concept

PoC Available for CVE-2026-1470

CWE Category CWE-95
Published Date Jan 27, 2026
Modified Date Feb 20, 2026
Exploit Status Available
Score 9.9 CVSS v3.1
Exploit Probability (EPSS)
18.72%

Vulnerability Summary

CVE-2026-1470: n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations.

CVSS v3.1
Source Entity [email protected]
Severity CRITICAL
9.9
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-1470 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/Ashwesker/Ashwesker-CVE-2026-1470
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Stack

No specific products linked.