Home / Jul 23, 2026 / Story
0
#5 The Hacker News general July 22, 2026 at 12:36 UTC

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

By [email protected] (The Hacker News)

AI Summary

CVE-2026-29059, a CVSS 7.5 unauthenticated path traversal in the open-source developer platform Windmill, is being actively exploited in the wild according to VulnCheck. The flaw resides in the 'get_log_file' API endpoint where an unsanitized filename parameter allows attackers to read arbitrary server files without credentials. Organizations using Windmill in CI/CD or AI agent workflows should patch immediately given confirmed in-the-wild exploitation.

Relevance score: 87.0/100

# More from July 23