CVE-2026-21894 | n8n-io n8n up to 2.2.1 Webhook Endpoint authentication spoofing (GHSA-jf52-3f2h-h9j5)
A vulnerability marked as critical has been reported in n8n-io n8n up to 2.2.1. Affected by this vulnerability is an unknown functionality of the component Webhook Endpoint. The manipulation leads to authentication bypass by spoofing.
This vulnerability is listed as CVE-2026-21894. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.