PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86078 n8n-io CVE debrief

A vulnerability in n8n, a workflow automation platform, allows for disruption of later requests due to improper handling of workflow summaries. The issue is fixed in versions 2.37.7 and 2.38.2. This vulnerability impacts n8n instances that use versions prior to 2.37.7 or 2.38.2. The summarizeWorkflowStructure function improperly handles workflow summaries, allowing for disruption of later requests. The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. Defenders and administrators of n8n instances should assess exposure and apply patches to prevent potential disruptions.

Vendor
n8n-io
Product
n8n
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-09-11
Advisory published
2026-09-08
Advisory updated
2026-09-11

Who should care

Defenders and administrators of n8n instances should assess exposure and apply patches to prevent potential disruptions. This vulnerability impacts n8n instances that use versions prior to 2.37.7 or 2.38.2. Defenders should verify exposure and apply patches to n8n instances, particularly those using versions prior to 2.37.7 or 2.38.2. Security teams and vulnerability management teams should review and monitor workflow configurations for unusual activity.

Why it matters

CVE-2026-86078 allows for disruption of later requests in n8n workflow automation platform. Defenders should verify exposure, apply patches, and monitor workflows.

  • Verify and apply patches to prevent disruption of n8n workflows
  • Review and monitor workflow configurations for unusual activity

Technical summary

The summarizeWorkflowStructure function in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts improperly handles workflow summaries, allowing for disruption of later requests. This issue is fixed in versions 2.37.7 and 2.38.2. The vulnerability impacts n8n instances that use versions prior to 2.37.7 or 2.38.2. There is limited information available on the specific attack vectors or exploits. Defenders should verify exposure and apply patches to n8n instances, particularly those using versions prior to 2.37.7 or 2.38.2.

Defensive priority

Defenders should prioritize verifying exposure and applying patches to n8n instances, particularly those using versions prior to 2.37.7 or 2.38.2.

Recommended defensive actions

  • Verify n8n instance versions and apply patches to ensure 2.37.7 or 2.38.2 or later are used
  • Review workflow configurations for potential exposure
  • Monitor for unusual activity or disruptions in n8n workflows
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. The summarizeWorkflowStructure function in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts improperly handles workflow summaries, allowing for disruption of later requests. This issue is fixed in versions 2.37.7 and 2.38.2. There is limited information available on the specific attack vectors or exploits. Defenders should verify exposure and apply patches to n8n instances, particularly those using versions 2.37

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86078 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86078

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86078 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86078

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.