CVE-2026-56360: n8n
Medium severity, CVSS 4.0. EPSS: 0.3% chance of exploitation in the next 30 days.
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
Affected products
- n8n n8n: before 1.123.18 (fixed in 1.123.18); from 2.0.0, before 2.6.2 (fixed in 2.6.2)
Published 2026-07-08. Last modified 2026-07-08.