CyberRota
← Ana sayfaya dön

CVE-2026-42233

CRITICAL · CVSS 9.8 EPSS %0.06 Public Exploit

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-04T19:16:05.847 · Çekilme zamanı: 2026-06-03T18:00:28.850384+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

Public Exploit Sinyali

Bu CVE için açıklama veya referanslarda public exploit / PoC / GitHub / Metasploit sinyali tespit edildi.

GitHub PoC Linkleri

Not: Bu bağlantılar yalnızca güvenlik araştırması ve doğrulama amacıyla listelenmiştir.

CVE
CVE-2026-42233
Severity
CRITICAL
CVSS
9.8
EPSS
%0.06
Oracle

Orijinal NVD Açıklaması

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the Limit field (e.g., from a webhook), an attacker could inject arbitrary SQL and exfiltrate data from the connected Oracle database. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.