PT-2026-56437 · N8N · N8N

·

CVE-2026-56360

·

Published

2026-02-26

·

Updated

2026-07-08

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.18 n8n versions prior to 2.6.2
Description The ZendeskTrigger node fails to verify HMAC-SHA256 signatures on Zendesk webhooks. This allows attackers who possess the webhook URL to send unsigned POST requests to trigger workflows using arbitrary malicious data. HMAC-SHA256 is a cryptographic hash function used to verify both the data integrity and the authenticity of a message.
Recommendations Update to version 1.123.18 or later. Update to version 2.6.2 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56360
GHSA-38C7-23HJ-2WGQ

Affected Products

N8N