Unauthenticated Path Traversal Vulnerability in Windmill Developer Platform
CVE-2026-29059
Key Information:
- Vendor
Windmill-labs
- Status
- Vendor
- CVE Published:
- 6 March 2026
Badges
What is CVE-2026-29059?
CVE-2026-29059 is an unauthenticated path traversal vulnerability affecting the Windmill Developer Platform, an open-source framework used for internal application development, including APIs, background jobs, workflows, and user interfaces. This vulnerability resides in the platform's get_log_file endpoint, where improper handling of the filename parameter allows attackers to manipulate file paths. Specifically, the filename is directly concatenated into the system's file path without adequate sanitization, giving attackers the ability to exploit directory traversal techniques using ../ sequences. This could lead to unauthorized access to sensitive files on the server, potentially compromising confidential data critical to an organization’s operational security.
Potential impact of CVE-2026-29059
-
Unauthorized File Access: Attackers can leverage this vulnerability to read arbitrary files on the server, which may contain sensitive data like configuration files, user information, or application credentials, leading to significant data breaches.
-
Increased Attack Surface: The ability to traverse directories could allow an attacker to gather intelligence about the server environment, potentially leading to further exploits or attacks against the system, increasing the overall risk to the organization’s infrastructure.
-
Reputation and Compliance Risks: If sensitive data is accessed and subsequently leaked, organizations may face severe repercussions, including reputational damage, loss of customer trust, and violations of compliance regulations, which could lead to legal liabilities.
Affected Version(s)
windmill < 1.603.3
News Articles
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
VulnCheck says attackers are exploiting Windmill CVE-2026-29059 to read server files, with about 170 vulnerable systems exposed in 24 countries.
3 weeks ago
References
CVSS V4
Timeline
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
