Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).

“The filename parameter is concatenated into

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Kagi Changelog (July 2): Heads, tails, and an AI toggle

Kagi Changelog (July 2): Heads, tails, and an AI toggle Source: Hacker News

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to

Polymarket has flooded social media with deceptive videos by paid creators

Polymarket has flooded social media with deceptive videos by paid creators Source: Hacker News