n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-unsigned-post-requests-in-zendesktrigger | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Jul 2026, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
N8n
N8n n8n |
|
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-unsigned-post-requests-in-zendesktrigger - Third Party Advisory |
08 Jul 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 14:17
Updated : 2026-07-08 19:32
NVD link : CVE-2026-56360
Mitre link : CVE-2026-56360
CVE.ORG link : CVE-2026-56360
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-290
Authentication Bypass by Spoofing
