PatchSiren cyber security CVE debrief
CVE-2026-86079 n8n CVE debrief
This PatchSiren debrief provides source-grounded defensive context for CVE-2026-86079, a vulnerability in the n8n workflow automation platform affecting Elasticsearch and ElasticSecurity nodes. The issue allows for potential unauthorized access to sensitive data or cluster administration endpoints due to improper handling of workflow-controlled index and document identifiers.
- Vendor
- n8n
- Product
- n8n
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-11
Who should care
Defenders responsible for n8n deployments, especially those utilizing Elasticsearch and ElasticSecurity nodes, should assess their exposure to this vulnerability and prioritize verification and remediation efforts.
Why it matters
CVE-2026-86079 allows potential unauthorized access to sensitive data or cluster administration endpoints in n8n workflow automation platform deployments using Elasticsearch and ElasticSecurity nodes. Defenders should verify exposure, prioritize updates or compensating controls, and monitor for potential security risks.
- Potential unauthorized access to sensitive data
- Potential access to cluster administration endpoints
- Need for verification of n8n deployment versions
- Priority for applying updates or compensating controls
Technical summary
The n8n workflow automation platform, prior to versions 1.123.76, 2.37.7, and 2.38.2, contains a vulnerability in its Elasticsearch and ElasticSecurity nodes. The issue arises from the interpolation of workflow-controlled index and document identifiers directly into REST request paths, potentially allowing unauthorized access to sensitive data or cluster administration endpoints. This vulnerability affects n8n deployments using Elasticsearch and ElasticSecurity nodes, allowing potential unauthorized access to sensitive data or cluster administration endpoints due to improper handling of workflow-controlled index and document identifiers.
Defensive priority
Defenders should prioritize verifying exposure in their n8n deployments, especially those using Elasticsearch and ElasticSecurity nodes, and assess the need for updates or compensating controls.
Recommended defensive actions
- Verify n8n deployment versions and assess exposure to CVE-2026-86079
- Apply updates to n8n to version 1.123.76, 2.37.7, or 2.38.2 as applicable
- Review workflow-controlled index and document identifiers for potential security risks
- Monitor for potential unauthorized access to sensitive data or cluster administration endpoints
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score of 6.3 and MEDIUM severity. The issue is fixed in n8n versions 1.123.76, 2.37.7, and 2.38.2. Defenders should verify exposure in their n8n deployments, especially those using Elasticsearch and ElasticSecurity nodes, and assess the need for updates or compensating controls. Evidence from the CVE Program and NVD detail page indicates potential unauthorized access to sensitive data or cluster administration endpoints. Limited source-prov
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86079 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86079
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86079 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86079
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/releases/tag/[email protected]
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/releases/tag/[email protected]
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/releases/tag/[email protected]
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/security/advisories/GHSA-f2cp-m7mv-8jpv
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.