Incorrect Default Permissions in Windmill Product by Windmill Labs
CVE-2026-47107

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
19 May 2026

What is CVE-2026-47107?

Windmill prior to version 1.703.2 is vulnerable due to an incorrect default permissions setup in nsjail sandbox configuration files. This issue arises because the /etc directory is bind-mounted without the necessary read-write restrictions. As a result, authenticated users can write arbitrary entries to critical files such as /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt during script executions within the sandbox environment. This vulnerability can be exploited by attackers to introduce persistent poisoned entries that affect subsequent script executions on the same worker pod. Consequently, adversaries may redirect hostnames, intercept DNS queries, conduct transparent HTTPS man-in-the-middle attacks, and access WM_TOKEN JWTs, potentially allowing them workspace-admin access to victim workspaces across different tenants.

Affected Version(s)

windmill 0

windmill 0 < 1.703.2

windmill f8467f38c8a053117ce62f96684cfb15ef792f08

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shai Dvash
.