TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Critical Zero-Click Flaw in n8n Allows Full Server Compromise

2026-03-12 · Read original ↗

ATT&CK techniques detected

1 predictions
T1190Exploit Public-Facing Application
61%
"##7 has been assigned a critical severity rating of 9. 4 ( cvss v4. 0 ). read more : maximum severity “ ni8mare ” bug lets hackers hijack n8n servers zero - click unauthenticated flaw : cve - 2026 - 27493 explained the second flaw was also reported by github on february 25 and is…"

Summary

The critical vulnerability affecting both cloud and self-hosted n8n instances requires no authentication or even n8n account to be exploited