CVE-2026-27494 | n8n-io n8n up to 1.123.21/2.9.2/2.10.0 Environment Variable N8N_RUNNERS_ENABLED exposure of sensitive system information to an unauthorized control sphere (GHSA-mmgg-m5j7-f83h / WID-SEC-2026-0532)
A vulnerability identified as problematic has been detected in n8n-io n8n up to 1.123.21/2.9.2/2.10.0. Affected by this issue is some unknown functionality of the component Environment Variable Handler. The manipulation of the argument N8N_RUNNERS_ENABLED leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is traded as CVE-2026-27494. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.