Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-54310 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-54310 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-54310 is a critical injection vulnerability in N8N, the open source workflow automation platform, affecting the TimescaleDB node integration and exploitable by authenticated users with workflow creation or modification privileges.

Technical Detail

The flaw exists in how N8N processes user-supplied parameters passed to the TimescaleDB node prior to versions 2.25.7 and 2.26.2, where insufficient input validation allows a crafted payload to be injected into database operations. An authenticated attacker with permission to create or edit workflows can supply malicious parameters to manipulate the underlying TimescaleDB query execution. The full description is truncated in available data, but given the CVSS score of 9.9, the likely impact includes unauthorized data access, data manipulation, or remote code execution within the database layer or host environment.

Exploitation Status

No known exploit exists for this vulnerability at this time. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploit maturity is assessed as none, meaning no public proof-of-concept or weaponized code has been confirmed as of June 30, 2026.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this vulnerability in available intelligence sources.

What To Do

Organizations running self-hosted N8N instances should upgrade immediately to version 2.25.7 or 2.26.2 or later, as both branches contain the patch. Given the CVSS score of 9.9 and the authenticated-but-low-privilege attack requirement, environments where multiple users have workflow creation rights are at elevated risk and should treat this as a priority patch. As an interim measure, restrict workflow creation and modification permissions to the minimum necessary set of trusted users. Audit existing workflows for unexpected or anomalous TimescaleDB node configurations. Monitor database logs for unusual query patterns originating from the N8N service account as a detection signal.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →