Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An identifier containing path separators or dot segments could select another index or a cluster administration endpoint under the stored Elasticsearch credential. The affected request construction includes packages/nodes-base/nodes/Elastic/Elasticsearch/GenericFunctions.ts and the missing toPathSegment encoding. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Path Injection in Elasticsearch and ElasticSecurity nodes allowing arbitrary index or cluster administration access
Action: Patch
AI Analysis

Impact

The vulnerability permits path injection by directly interpolating workflow‑controlled index and document identifiers into REST request paths without proper encoding. An attacker can supply an identifier that contains path separators or dot segments, causing the request to target a different index or a cluster administration endpoint under the stored Elasticsearch credentials. This can lead to unauthorized data discovery, modification or deletion, and potentially elevate privileges within an Elasticsearch cluster.

Affected Systems

The issue affects n8n-io:n8n workflows running any of the following versions: any release before 1.123.76, 2.37.7, or 2.38.2.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires input of a malicious identifier in a workflow; therefore the attack vector is likely an insider or an attacker who has gained the ability to create or modify workflows. No publicly available exploit is known, but the risk remains if untrusted users can define identifiers that are passed to Elasticsearch nodes.

Generated by OpenCVE AI on September 9, 2026 at 09:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to version 1.123.76, 2.37.7, or 2.38.2 or later to receive the fixed code that encodes path segments properly.
  • If an upgrade is not immediately possible, validate or sanitize all workflow identifiers before they are passed to the Elasticsearch or ElasticSecurity nodes by removing or escaping path separators and dot segments.
  • Restrict the creation and modification of workflows that use these nodes to trusted users only, and monitor for anomalous identifier patterns.

Generated by OpenCVE AI on September 9, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f2cp-m7mv-8jpv n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An identifier containing path separators or dot segments could select another index or a cluster administration endpoint under the stored Elasticsearch credential. The affected request construction includes packages/nodes-base/nodes/Elastic/Elasticsearch/GenericFunctions.ts and the missing toPathSegment encoding. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T15:13:30.345Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86079

cve-icon Vulnrichment

Updated: 2026-09-09T15:13:27.481Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:16.813

Modified: 2026-09-11T18:21:33.190

Link: CVE-2026-86079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')