CVE-2026-85167 | n8n-io n8n prior 2.35.4/2.36.2 Elasticsearch Document Get All code injection
A vulnerability marked as problematic has been reported in n8n-io n8n. Impacted is an unknown function of the component Elasticsearch Document Get All/Google Cloud Firestore Document Query. The manipulation leads to code injection.
This vulnerability is documented as CVE-2026-85167. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More