CVE-2026-56360

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-07-08 14:17

Updated : 2026-07-08 19:32


NVD link : CVE-2026-56360

Mitre link : CVE-2026-56360

CVE.ORG link : CVE-2026-56360


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-290

Authentication Bypass by Spoofing