#VU122487 Authentication bypass by spoofing in n8n - CVE-2026-21894
Published: February 9, 2026
n8n
n8n
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication checks in Stripe Trigger node. A remote non-authenticated attacker can send a specially crafted HTTP POST request to the application and gain access to sensitive information or perform certain actions with the application.