CVE-2026-1470
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime.
An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 21%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1005Data from Local Systemcollection80 % - Impacto secundario
T1565.002Transmitted Data Manipulationimpact75 %
Vulnerabilidad RCE en evaluador de expresiones de n8n. AV:N/PR:L indica explotación remota con autenticación (T1210). Permite ejecución arbitraria de código (T1059), acceso a datos sensibles (T1005) y modificación de workflows (T1565.002).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-95
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-1470",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-1470",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-01-27T14:35:25.784260Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "reefs@jfrog.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "reefs@jfrog.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.123.17",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.4.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.5.0",
"lessThan": "2.5.1",
"versionType": "semver"
}
],
"packageName": "n8n",
"collectionURL": "https://www.npmjs.com"
}
]
}
],
"published": "2026-01-27T15:15:57.143",
"references": [
{
"url": "https://github.com/n8n-io/n8n/commit/aa4d1e5825829182afa0ad5b81f602638f55fa04",
"tags": [
"Patch"
],
"source": "reefs@jfrog.com"
},
{
"url": "https://research.jfrog.com/vulnerabilities/n8n-expression-node-rce/",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "reefs@jfrog.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "reefs@jfrog.com",
"description": [
{
"lang": "en",
"value": "CWE-95"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime.\n\nAn authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations."
},
{
"lang": "es",
"value": "n8n contiene una crítica vulnerabilidad de ejecución remota de código (RCE) en su sistema de evaluación de expresiones de flujo de trabajo. Las expresiones proporcionadas por usuarios autenticados durante la configuración del flujo de trabajo pueden ser evaluadas en un contexto de ejecución que no está suficientemente aislado del tiempo de ejecución subyacente.\n\nUn atacante autenticado podría abusar de este comportamiento para ejecutar código arbitrario con los privilegios del proceso de n8n. La explotación exitosa puede llevar al compromiso total de la instancia afectada, incluyendo el acceso no autorizado a datos sensibles, la modificación de flujos de trabajo y la ejecución de operaciones a nivel de sistema."
}
],
"lastModified": "2026-06-17T10:15:51.000",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8FB57226-E06A-4156-9A24-C320BCA37EB1",
"versionEndExcluding": "1.123.17"
},
{
"criteria": "cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "52026A74-2A68-453E-B465-A30DD1819C2F",
"versionEndExcluding": "2.4.5",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:n8n:n8n:2.5.0:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "2BBB681B-B071-4A5B-90C0-EA5625C3D5FF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "reefs@jfrog.com"
}