CVE-2026-103253
Deferred Deferred - Pending Action

SQL Injection in n8n Oracle Database Node

Vulnerability report for CVE-2026-103253, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with the credential's privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
n8n n8n to 1.123.80 (exc)
n8n n8n From 2.0.0 (inc) to 2.39.6 (exc)
n8n n8n From 2.40.0 (inc) to 2.40.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a SQL injection vulnerability in n8n's Oracle Database node affecting versions before 1.123.80, 2.39.6, and 2.40.1. Attackers can inject single quotes into table or schema fields during the Delete Table Drop operation to append malicious SQL statements. This allows execution of arbitrary DDL or DML commands with the database credentials' privileges.

Detection Guidance

To detect this vulnerability, check if your n8n instance is running a vulnerable version (before 1.123.80, 2.39.6, or 2.40.1). Inspect Oracle Database node workflows for Delete Table Drop operations with untrusted input in table or schema fields. Monitor database logs for unusual DDL or DML commands.

Impact Analysis

Exploitation could lead to unauthorized database modifications including unrecoverable table deletions, data manipulation, or schema changes depending on the compromised credentials' privileges. Attackers might gain control over database operations without needing user interaction or privileges.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized data access or destruction. GDPR may be impacted through potential data breaches, while HIPAA could be compromised if protected health information is altered or deleted. Organizations must patch to maintain compliance.

Mitigation Strategies

Immediately update n8n to versions 1.123.80, 2.39.6, or 2.40.1 or later. Disable the Oracle Database node in workflows if not needed. Restrict n8n access to trusted networks and users. Audit existing workflows for suspicious Oracle Database operations. Limit database credential privileges to the minimum required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103253. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart