THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f2cp-m7mv-8jpv (medium) — n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

[GHSA] GHSA-f2cp-m7mv-8jpv (medium) — n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

medgithub_advisoriesPublished 2026-09-10

GHSA-f2cp-m7mv-8jpv Severity: medium CVE: CVE-2026-86079

n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

## Impact

The Elasticsearch and ElasticSecurity nodes built REST endpoints by interpolating user-provided identifiers straight into the request path. A value containing path separators or dot segments changed which endpoint the request actually reache

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f2cp-m7mv-8jpv