CVE Tools

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

The Hacker NewsBy The Hacker News

Reported exploitedWindmill platform

Our summary

A critical vulnerability in the open-source developer platform Windmill is being actively exploited in the wild, allowing attackers to read arbitrary server files without authentication. The flaw, tracked as CVE-2026-29059 (CVSS score: 7.5), affects the 'get_log_file' endpoint and enables path traversal attacks. Attackers can exploit this to access sensitive data like the SUPERADMIN_SECRET environment variable, which grants elevated privileges. A fix was released in version 1.603.3 in January 2026, but many systems remain vulnerable.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store