Authorization Bypass Vulnerability in Windmill Labs Windmill
CVE-2026-72541
6.5MEDIUM
What is CVE-2026-72541?
Windmill Labs' Windmill, up to version 1.783.0, contains a missing authorization vulnerability that permits authenticated workspace members to overwrite any resource type schema through the update_resource_type endpoint. This endpoint lacks the administrator permission check that the corresponding delete_resource_type endpoint successfully implements, enabling attackers with workspace member privileges to corrupt critical resource definitions. Such unauthorized changes can disrupt workflows that rely on the integrity of these resource types, leading to potential operational failures and security incidents.
Affected Version(s)
Windmill 0 <= 1.783.0
