n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-unsigned-post-requests-in-zendesktrigger | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-08 14:17
Updated : 2026-07-08 19:32
NVD link : CVE-2026-56360
Mitre link : CVE-2026-56360
CVE.ORG link : CVE-2026-56360
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-290
Authentication Bypass by Spoofing
