Sploitus

CVE-2026-21858

39 known exploits for CVE-2026-21858

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.

Affected products
N8N
n8n
< 1.121.0
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
78.4% (100th percentile)
Weakness
CWE-20
NVD status
Analyzed
Published
2026-01-07
CVE-2026-21858 at NVD
Authoritative description, scoring and affected products

39 known exploits for CVE-2026-21858

Proof-of-concept code and exploit modules indexed by Sploitus

Research-CVE-2026-21858
2026-09-10 KitPloitKITPLOIT
CVE-2026-21858
2026-09-10 KitPloitKITPLOIT
CVE-2026-21858
2026-09-10 KitPloitKITPLOIT
Ashwesker-CVE-2026-21858
2026-09-10 KitPloitKITPLOIT
CVE-2026-21858
2026-09-10 KitPloitKITPLOIT
CVE-2026-21858
2026-09-10 KitPloitKITPLOIT
CVE-2026-21858-and-CVE-2025-68613
2026-09-10 KitPloitKITPLOIT
SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit
2026-09-09 KitPloitKITPLOIT
PoC-CVE-2026-21858
2026-09-09 KitPloitKITPLOIT
Ni8mare
2026-09-09 KitPloitKITPLOIT
CVE-2026-21858
2026-09-09 KitPloitKITPLOIT
CVE-2026-21858
2026-09-07 KitPloitKITPLOIT
CVE-2026-21858
2026-09-07 KitPloitKITPLOIT
cve-2026-21858
2026-09-07 KitPloitKITPLOIT
n8n-cve-2026-21858
2026-09-06 KitPloitKITPLOIT
cve
2026-08-30 KitPloitKITPLOIT
Exploit for Improper Input Validation in N8N
2026-08-21 yym8538GITHUB
cve-2026-poc-collection
2026-08-06 TreasureBoy99GITHUB
cve-2026-poc-collection
2026-08-03 TreasureBoy520GITHUB
CVE-2026-21858-and-CVE-2025-68613
2026-07-31 GiangdurianGITHUB
Exploit for Improper Input Validation in N8N
2026-07-21 qianlijaingshanGITHUB
Exploit for Improper Input Validation in N8N
2026-06-21 FomovetGITHUB
cve-2026-poc-collection
2026-05-21 XZ1r0GITHUB
Exploit for Improper Input Validation in N8N
2026-04-16 masterwokGITHUB
Exploit for Improper Input Validation in N8N
2026-04-09 kaleth4GITHUB
Exploit for Improper Input Validation in N8N
2026-02-24 bamov970GITHUB
πŸ“„ n8n Workflow Automation Remote Configuration / Admin Data Extraction
2026-02-17 indoushkaPACKETSTORMRuby
n8n arbitrary file read
2026-02-16 dor attias, msutovsky-r7METASPLOITRuby
Exploit for Improper Input Validation in N8N
2026-02-11 EQSTLabGITHUB
πŸ“„ n8n 2.0.0-rc.4 Remote Command Execution
2026-01-30 indoushkaPACKETSTORMPHP
Exploit for Improper Input Validation in N8N
2026-01-30 Alhakim88GITHUB
Exploit for Improper Input Validation in N8N
2026-01-24 NOTTIBOY137GITHUB
Exploit for Improper Input Validation in N8N
2026-01-21 MOGMUNIGITHUB
Exploit for Improper Input Validation in N8N
2026-01-20 SystemVllGITHUB
Exploit for Improper Input Validation in N8N
2026-01-20 sec-dojo-comGITHUB
Exploit for Improper Input Validation in N8N
2026-01-17 sastraadiwiguna-purpleeliteteamingGITHUB
Exploit for CVE-2026-21858
2026-01-12 cropnetGITHUB
CVE-2026-21858
2026-01-07 GitHub_MUNKNOWN
Exploit for CVE-2026-21858
2026-01-07 ChocapikkGITHUB