InfoSec News Nuggets 01/08/2026
Critical n8n Vulnerability (CVSS 10.0) Enables Unauthenticated Attackers to Take Full Control Security researchers disclosed CVE-2026-21858, a maximum-severity flaw in the n8n workflow automation platform nicknamed "Ni8mare" that allows unauthenticated remote attackers to gain complete control over vulnerable instances. The vulnerability stems from a Content-Type confusion issue in n8n's webhook and file handling mechanism, enabling attackers to extract sensitive secrets, forge administrator access, and execute arbitrary commands on the server without requiring any credentials. The…