n8n
Leading open-source AI workflow automation platform now embedded as the orchestration layer in SAP Joule Studio (May 12, 2026 strategic investment of ~$60M doubled valuation to $5.2B in 7 months; native embedding GA by Q3 2026).
Dimension breakdown
Score · confidenceLeading open-source AI workflow automation platform now embedded as the orchestration layer in SAP Joule Studio (May 12, 2026 strategic investment of ~$60M doubled valuation to $5.2B in 7 months; native embedding GA by Q3 2026). Combined with $40M+ ARR (5.5x YoY), 1,400+ enterprise customers (Vodafone, Microsoft, Delivery Hero, KPMG, Volkswagen, Twitch), 1.7M monthly active builders, ~190K GitHub stars (100M+ Docker pulls), and bidirectional MCP (now auto-generates/validates/self-corrects workflows) / HITL / Git source-control capabilities, viability is Market-Leader caliber for AI-native workflow automation.
critical-security-vuln cap remains in force — 10+ CVSS 9.4-10.0 RCE CVEs across Nov 2025–May 2026, CISA KEV listing (CVE-2025-68613) with confirmed in-the-wild exploitation (VulnCheck/Shadowserver/GreyNoise canaries, Zerobot, public PoCs) and two distinct patch bypasses (CVE-2026-25049 bypassed 68613; CVE-2026-44791 bypassed 42232).
May 2026 batch (CVE-2026-42231/42232/44789/44790/44791 prototype-pollution + CVE-2026-27493 Form-node) plus a June 16 2026 batch (CVE-2026-54306 webhook prototype-pollution RCE, fixed 2.25.7/2.26.2; CVE-2026-54312 MSSQL-node prototype-pollution, fixed 2.24.0; Singapore CSA AL-2026-057) keep resetting the 90-day clean window; earliest cap removal late-September 2026 at soonest. Latest 2.22.x line carries the fixes, but self-hosted operators must maintain aggressive patching cadence.
Not a coding assistant — orchestrates AI workflows.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
Critical security vuln
securityTemporaryUnpatched critical security vulnerability
Caps Enterprise / Compliance at 25
Removed when — CVE patched and verified, or security incident resolved with post-mortem published
Status rationale
Tracked because the convergence of SAP's strategic investment (May 12 2026 at $5.2B, ~$60M / 1.3% stake), native Joule Studio embedding (GA Q3 2026), $40M+ ARR, 1,400+ named enterprise customers, and dominant open-source/community footprint (~190K stars, 1.7M monthly builders, 100M+ Docker pulls) clears the Tracked evidence bar: official docs, multi-source enterprise validation, and analyst coverage are abundant — no hands-on testing yet. Cannot reach Assessed in this evaluation because (a) critical-security-vuln cap remains active and (b) no internal hands-on evaluation has been performed.
The security pattern (10+ critical RCE CVEs in 7 months, CISA KEV with confirmed in-the-wild exploitation, two distinct patch bypasses) is the gating constraint on further promotion.
Movement triggers
Promote to Assessed if: 90-day clean security window achieved (earliest late-September 2026, contingent on no new critical CVE after the June 16 54306/54312 batch) AND first hands-on internal pilot or third-party security audit completed; OR SAP Joule Studio integration ships GA (Q3 2026) with documented enterprise governance overlay. Promote to Validated only after: cap fully removed, named WWT or peer-firm production deployment, and at least one full quarter of clean CVE record.
Demote back to Detected if: new critical CVE in 30-day window indicating continued systemic regression, broad active exploitation confirmed in customer environments, SAP partnership unwinds, or material funding/leadership instability.
Risks & limitations
Critical Security Vuln
ModerateRadar cap: critical-security-vuln
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category