Fetching from the wire…
Public story · 2026-03-16 · source-backed
Any n8n web form — no credentials needed — leaks arbitrary server files, enabling full server takeover. n8n is widely deployed as an agentic workflow orchestrator; exposed web forms are the common entry point. CSO Online
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source / Shared topic / Earlier coverage
Both cover CSO Online, CVSS; cite the same source (CSO Online); overlapping topics (arbitrary, cve-2026-21858, cvss).
Shared entities / Shared topic / What happened next
Both cover CVE, CVSS; overlapping topics (arbitrary, credential, cvss, server); picks up the CVE thread on 2026-07-28.
Both cover CVE, CVSS; overlapping topics (common, cvss, leak, server); picks up the CVE thread on 2026-07-01.
Both cover CVE, CVSS; overlapping topics (arbitrary, credential, cvss, server); picks up the CVE thread on 2026-03-20.
Shared entities / Shared topic / Earlier coverage
Both cover CVE, CVSS; overlapping topics (credential, cve-2026-21858, cvss, full); earlier CVE coverage from 2026-02-23.
Shared entities / Shared topic / What happened next / Tension
Both cover CVE, CVSS; overlapping topics (full, server); picks up the CVE thread on 2026-03-23.
Shared entities / Shared topic / What happened next
Both cover CVE, CVSS; overlapping topics (credential, cvss, server); picks up the CVE thread on 2026-04-03.
Both cover CVE, CVSS; overlapping topics (cvss, exposed, form); picks up the CVE thread on 2026-03-25.