Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

Read full story on The Hacker News
Share
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
AI disclosure

Summary

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}"). "The filename parameter is concatenated into

Original reporting

Open original source
Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.