HomeCVE Intelligence › CVE-2026-54052
CVSS 9.9 CRITICAL Vulnerability

CVE-2026-54052: n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, pr…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's loc…

9.9CVSS Score
CRITICALSeverity
NOCISA KEV
0.4%EPSS Score
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-54052
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeVulnerability
CVSS Score9.9 (CRITICAL)
EPSS Score0.4% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-54052","confidence_score":23.5,"first_seen":"2026-07-18","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-54052 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence