MEDIUMVulnerability

CVE-2026-85167

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression values directly into the query string before parsing. A value containing quote and brace characters can close the intended field and introduce new query operators, turning an intended single-document lookup into a full-collection read.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00232
cve_id
CVE-2026-85167
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-03T13:06:24.003
last_modified
2026-09-10T19:53:08.683
epss_percentile
0.14225

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Data Query Logic

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85167 — Ninja Signal Threat Intelligence | Ninja Signal