All verified exploits

CVE-2026-21858 Form Webhook Arbitrary File Read (Ni8mare)

Pentest critical n8n Added cve-verified-cve-2026-21858

Detects n8n instances where form webhook endpoints accept Content-Type: application/json, bypassing the multipart file upload parser. An unauthenticated attacker can control the files.filepath field to read any file on the server, including /etc/passwd, n8n encryption keys, and the database. Combined with CVE-2025-68613, this enables full RCE.

Is your app exploitable through CVE-2026-21858?

Scan your domain free