Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4310 articles · 196690 vulns · 37/41 feeds (7d)
← Back to list
4.0
CVE-2026-56360PATCHED
n8n · n8n

n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger

Description

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

Affected Products

VendorProductVersions
n8nn8n0, 2.0.0

References

  • https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq(vendor-advisory)
  • https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-unsigned-post-requests-in-zendesktrigger(third-party-advisory)

Related News (1 articles)

Tier C
VulDB47d ago
CVE-2026-56360 | n8n up to 1.123.17/2.6.1 ZendeskTrigger data authenticity
→ No new info (linked only)
CVSS 3.14.0 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.123.182.6.2
CWECWE-290
PublishedJul 8, 2026
Last enriched47d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-59259EXP
n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
MEDIUMCVE-2026-59253
n8n - Improper Authorization in Workflow Assignment to Folders
MEDIUMCVE-2026-58661
n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
MEDIUMCVE-2026-59254EXP
n8n - External Secrets Disclosure via Workflow Node Expressions
NONECVE-2026-56354EXP
n8n - Cross-Site Scripting and Open Redirect in Form Node

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 8, 2026
Discovered by ZDM
Jul 8, 2026
Updated: severity, affectedVersions
Jul 8, 2026
Patch Available
Jul 8, 2026

Version History

v2
Last enriched 47d ago
v2Tier C47d ago

Updated severity to CRITICAL, marked exploit availability as false, and added affected versions 1.123.17 and 2.6.1.

severityaffectedVersions
via VulDB
v147d ago

Initial creation