Critical n8n Vulnerability Rated CVSS 10.0 Requires Upgrade to 1.121.0

THE BRIEF
Schneier on Security reported a critical vulnerability in n8n, identified as CVE-2026-21858 and assigned a CVSS score of 10.0. The report says the flaw enables attackers to take over locally deployed n8n instances and may affect an estimated 100,000 servers globally. No official workaround was available in the supplied report. Users are advised to upgrade to n8n version 1.121.0 or later to remediate the vulnerability. The item links to three technical sources and two news reports, but the supplied material does not provide additional technical details about the flaw, the affected versions, or confirmed exploitation. Organizations running n8n locally should therefore treat the report as a high-priority patching signal, identify relevant deployments, and check whether they meet the stated remediation version. Teams should also track official n8n guidance for any further clarification or changes. This brief reflects the claims in the named source and does not independently verify the estimated exposure or takeover capability.
WHY IT MATTERS
The reported CVSS 10.0 rating and claimed takeover capability make this a high-priority issue for organizations that operate n8n locally. The estimated global server count indicates potentially broad exposure, but the supplied report does not establish how many systems are vulnerable or whether exploitation has occurred. Because no official workaround is listed, version 1.121.0 or later is the stated remediation path. The key near-term challenge is finding every local deployment and confirming its version.
WHO SHOULD CARE
Teams responsible for locally deployed n8n instances, vulnerability management, platform operations, and security leadership should care. Organizations using n8n through internal automation environments should inventory deployments and verify that each one reaches the stated fixed version.
WHAT TO DO NOW
- Inventory locally deployed n8n instances and record the version running on each system.
- Upgrade identified instances to n8n version 1.121.0 or later.
- Prioritize systems that cannot be upgraded and monitor official n8n guidance because no official workaround is listed.
- Review available monitoring data for unusual activity while remediation is pending, without assuming exploitation has occurred.
VERIFICATION NOTE
Reported by Schneier on Security; this archive brief does not add independent confirmation beyond the cited source.