#5
The Hacker News
general
July 22, 2026 at 12:36 UTC
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
By [email protected] (The Hacker News)
AI Summary
CVE-2026-29059, a CVSS 7.5 unauthenticated path traversal in the open-source developer platform Windmill, is being actively exploited in the wild according to VulnCheck. The flaw resides in the 'get_log_file' API endpoint where an unsanitized filename parameter allows attackers to read arbitrary server files without credentials. Organizations using Windmill in CI/CD or AI agent workflows should patch immediately given confirmed in-the-wild exploitation.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →