CVE-2026-71539

8.9

n8n-io · n8n

A Time-of-check Time-of-use (TOCTOU) race condition exists in the n8n workflow automation platform that could allow authenticated users to impact system integrity.

Executive summary

A race condition vulnerability in the n8n workflow automation platform, identified as CVE-2026-71539, poses a high risk to system integrity for authenticated users.

Vulnerability

This vulnerability is a Time-of-check Time-of-use (TOCTOU) race condition (CWE-367). It requires an attacker to have low-level authenticated access to the platform to exploit the flaw.

Business impact

Successful exploitation of this TOCTOU race condition could lead to unauthorized data modification or system instability within the workflow environment. Given the CVSS score of 8.9, this vulnerability is classified as high severity, reflecting the potential for significant impact on automated business processes and data handled by the n8n platform.

Remediation

Immediate Action: Update the n8n installation to version 1.123.64, 2.29.8, or 2.30.1 immediately to apply the vendor-supplied fix.

Proactive Monitoring: Monitor system access logs for unusual patterns or bursts of requests that could indicate an attempt to exploit race conditions during workflow execution.

Compensating Controls: Ensure that the n8n instance is protected by robust network access controls, limiting exposure to untrusted users who could leverage this vulnerability.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this vulnerability necessitates prompt action to secure your workflow automation environment. Administrators must prioritize updating to the patched versions provided by n8n-io to mitigate the risk of race condition exploitation.

More n8n-io CVEs