Junglewise Threat Intelligence

CVE-2026-56360: n8n signature verification bypass in ZendeskTrigger node

CVE-2026-56360 · Severity: medium · CVSS 4 · Published 2026-07-08

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that integrates with third-party services like Zendesk through trigger nodes. The Zendesk Trigger node fails to verify HMAC-SHA256 signatures on incoming webhook requests, allowing an attacker who discovers the webhook URL to send forged requests and execute arbitrary workflow logic. This could enable unauthorized data injection or manipulation of business processes that depend on genuine Zendesk events.

Technical details

The vulnerability is an authentication bypass (CWE-290) in the n8n Zendesk Trigger node. The node receives webhooks from Zendesk but does not validate the HMAC-SHA256 signature that Zendesk cryptographically attaches to every outbound webhook. An attacker with knowledge of the publicly exposed webhook URL can send unsigned POST requests with arbitrary payload data, bypassing the signature verification control entirely. The attack is network-accessible, has low complexity, and requires no privileges or user interaction. The attacker can inject malicious data into workflows that process Zendesk events, potentially affecting data integrity and business logic. Patches are available in n8n versions 1.123.18 and 2.6.2, where signature verification was implemented.

Affected products

  • n8n n8n <1.123.18, >=2.0.0 <2.6.2

Timeline

  • 2026-02-25: disclosed: GHSA-38c7-23hj-2wgq published
  • 2026-01-28: patched: Patch merged for version 2.6.2 (commit 3839e310)
  • 2026-01-29: patched: Patch merged for version 1.123.18 (commit c6520e4e)

References

Related threats