Unauthenticated Path Traversal Vulnerability in Windmill Developer Platform
CVE-2026-29059

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 March 2026

Badges

📈 Score: 1,800👾 Exploit Exists📰 News Worthy

What is CVE-2026-29059?

CVE-2026-29059 is an unauthenticated path traversal vulnerability affecting the Windmill Developer Platform, an open-source framework used for internal application development, including APIs, background jobs, workflows, and user interfaces. This vulnerability resides in the platform's get_log_file endpoint, where improper handling of the filename parameter allows attackers to manipulate file paths. Specifically, the filename is directly concatenated into the system's file path without adequate sanitization, giving attackers the ability to exploit directory traversal techniques using ../ sequences. This could lead to unauthorized access to sensitive files on the server, potentially compromising confidential data critical to an organization’s operational security.

Potential impact of CVE-2026-29059

  1. Unauthorized File Access: Attackers can leverage this vulnerability to read arbitrary files on the server, which may contain sensitive data like configuration files, user information, or application credentials, leading to significant data breaches.

  2. Increased Attack Surface: The ability to traverse directories could allow an attacker to gather intelligence about the server environment, potentially leading to further exploits or attacks against the system, increasing the overall risk to the organization’s infrastructure.

  3. Reputation and Compliance Risks: If sensitive data is accessed and subsequently leaked, organizations may face severe repercussions, including reputational damage, loss of customer trust, and violations of compliance regulations, which could lead to legal liabilities.

Affected Version(s)

windmill < 1.603.3

News Articles

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

VulnCheck says attackers are exploiting Windmill CVE-2026-29059 to read server files, with about 170 vulnerable systems exposed in 24 countries.

3 weeks ago

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.