
Critical N8N Workflow Automation Platform Vulnerabilities Enable Remote Code Execution and Credential Exposure
cybersecurityvulnerabilityn8nremote-code-executionRCECVE-2026-27577CVE-2026-27493workflow-automationcredential-exposurepatchsecurity-flaw
Cybersecurity researchers disclosed two now-patched critical security flaws in the n8n workflow automation platform, enabling arbitrary command execution and credential exposure. The vulnerabilities include CVE-2026-27577 (CVSS score: 9.4), an expression sandbox escape leading to remote code execution (RCE), and CVE-2026-27493 (CVSS score: 9.5), described as unauthenticated. Both flaws were addressed in recent patches, though no specific disclosure or patch dates were provided. The impacts involve unauthorized remote code execution and potential access to stored credentials within the platform. No details on exploitation in the wild or affected versions were mentioned.