PatchSiren cyber security CVE debrief
CVE-2026-86078 n8n-io CVE debrief
A vulnerability in n8n, a workflow automation platform, allows for disruption of later requests due to improper handling of workflow summaries. The issue is fixed in versions 2.37.7 and 2.38.2. This vulnerability impacts n8n instances that use versions prior to 2.37.7 or 2.38.2. The summarizeWorkflowStructure function improperly handles workflow summaries, allowing for disruption of later requests. The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. Defenders and administrators of n8n instances should assess exposure and apply patches to prevent potential disruptions.
- Vendor
- n8n-io
- Product
- n8n
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-11
Who should care
Defenders and administrators of n8n instances should assess exposure and apply patches to prevent potential disruptions. This vulnerability impacts n8n instances that use versions prior to 2.37.7 or 2.38.2. Defenders should verify exposure and apply patches to n8n instances, particularly those using versions prior to 2.37.7 or 2.38.2. Security teams and vulnerability management teams should review and monitor workflow configurations for unusual activity.
Why it matters
CVE-2026-86078 allows for disruption of later requests in n8n workflow automation platform. Defenders should verify exposure, apply patches, and monitor workflows.
- Verify and apply patches to prevent disruption of n8n workflows
- Review and monitor workflow configurations for unusual activity
Technical summary
The summarizeWorkflowStructure function in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts improperly handles workflow summaries, allowing for disruption of later requests. This issue is fixed in versions 2.37.7 and 2.38.2. The vulnerability impacts n8n instances that use versions prior to 2.37.7 or 2.38.2. There is limited information available on the specific attack vectors or exploits. Defenders should verify exposure and apply patches to n8n instances, particularly those using versions prior to 2.37.7 or 2.38.2.
Defensive priority
Defenders should prioritize verifying exposure and applying patches to n8n instances, particularly those using versions prior to 2.37.7 or 2.38.2.
Recommended defensive actions
- Verify n8n instance versions and apply patches to ensure 2.37.7 or 2.38.2 or later are used
- Review workflow configurations for potential exposure
- Monitor for unusual activity or disruptions in n8n workflows
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. The summarizeWorkflowStructure function in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts improperly handles workflow summaries, allowing for disruption of later requests. This issue is fixed in versions 2.37.7 and 2.38.2. There is limited information available on the specific attack vectors or exploits. Defenders should verify exposure and apply patches to n8n instances, particularly those using versions 2.37
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86078 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86078
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86078 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86078
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/releases/tag/[email protected]
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/releases/tag/[email protected]
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/security/advisories/GHSA-679f-58pq-4v2c
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.