Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Reported exploitedWindmill platformOur summary
A critical vulnerability in the open-source developer platform Windmill is being actively exploited in the wild, allowing attackers to read arbitrary server files without authentication. The flaw, tracked as CVE-2026-29059 (CVSS score: 7.5), affects the 'get_log_file' endpoint and enables path traversal attacks. Attackers can exploit this to access sensitive data like the SUPERADMIN_SECRET environment variable, which grants elevated privileges. A fix was released in version 1.603.3 in January 2026, but many systems remain vulnerable.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.