SQL injection in n8n - #VU150765
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify or delete database data.
The vulnerability exists due to SQL injection in the Oracle Database node Delete Table → Drop operation when processing table or schema values bound to untrusted upstream data. A remote attacker can supply crafted values containing SQL to modify or delete database data.
Injected statements execute with the privileges of the connected database credential.