CVE-2026-56360
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.0 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Vulnerability Description
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-290
Source
NVD
Vendor
n8n
Product
n8n
Discussion (0)
Add Comment
No comments yet. Be the first!