
AI
n8n's 'authenticated-only' RCE bug is scarier than it sounds — half your team can trigger it
CVE-2026-33696 needs zero exploits and zero admin rights — just permission to edit a workflow, which in most n8n setups is basically everyone.
Lena Fischer · 1h ago · 6 min