Back to Intel

Intel Node

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

mediumvulnerability2026-07-22T12:36:36+00:00source excerpt
vulnerabilitycveexploitation

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}").

Read Original Source