PT-2026-23658 · Windmill · Windmill

·

CVE-2026-29059

·

Published

2026-03-06

·

Updated

2026-07-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windmill versions prior to 1.603.3 Nextcloud Flow versions prior to 1.3.0
Description An unauthenticated path traversal flaw exists in the Windmill developer platform. The issue occurs at the /api/w/{workspace}/jobs u/get log file/{filename} endpoint, where the filename parameter is concatenated into a file path without proper sanitization. This allows an attacker to use ../ sequences to read arbitrary files on the server. Real-world incidents of active exploitation have been observed, where the flaw was used to leak credentials, access the SUPERADMIN SECRET, and in some cases, achieve root shell access and remote code execution. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update Windmill to version 1.603.3 or later. Update Nextcloud Flow to version 1.3.0 or later. Restrict access to the /api/w/{workspace}/jobs u/get log file/{filename} endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29059
GHSA-24FR-44F8-FQWG

Affected Products

Windmill