CVE-2026-56360

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

08 Jul 2026, 19:32

Type Values Removed Values Added
First Time N8n
N8n n8n
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq - () https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-unsigned-post-requests-in-zendesktrigger - () https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-unsigned-post-requests-in-zendesktrigger - Third Party Advisory

08 Jul 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 14:17

Updated : 2026-07-08 19:32


NVD link : CVE-2026-56360

Mitre link : CVE-2026-56360

CVE.ORG link : CVE-2026-56360


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-290

Authentication Bypass by Spoofing