Back to CVE List

CVE-2026-56360

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.0 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Vulnerability Description

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-290
Source
NVD
Vendor
n8n
Product
n8n

External References

Discussion (0)

Add Comment

No comments yet. Be the first!