Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}"). "The filename parameter is concatenated into
This headline and summary belong to the original publisher and are shown here with attribution for our readers; the complete article is available only at the source linked above. Curation and any commentary are by Addroit Nexus and do not imply endorsement by the publisher. Spotted an error or want a story removed? Tell us and we act quickly.