CVE-2026-22683Disclosure(nextcloud / flow)

MEDIUMCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nextcloud flow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not enforce the Operator restriction on workspace endpoints, allowing an Operator to create and update scripts, flows, apps, and raw_apps. Since Operators can also execute scripts via the jobs API, this allows direct privilege escalation to remote code execution within the Windmill deployment. This vulnerability has existed since the introduction of the Operator role in version 1.56.0.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flow
  • windmill

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-07); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Products
flowwindmill

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-08: 2Mentions · 2026-07-23: 1Mentions · 2026-09-28: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-04-08: 2Exploit Tool / Code · 2026-04-08: 1Patch / Workaround · 2026-04-08: 2Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 2Technical Details · 2026-07-23: 104-0704-0807-2309-2810-06
Signal classification2 categories
Disclosure
360.0%
PoC
240.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-082
PoC2
2026-07-231
Disclosure1
Full discourse7 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-22683 - high 🚨 Windmill < 1.603.3 - Operator Authorization Bypass > Windmill versions 1.276.0 through 1.603.2 contain an authorization bypass vulnerabili... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-22683 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-22683 is an operator authorization bypass affecting Windmill versions 1.276.0–1.603.2. The tweet offers basic vulnerability info but no exploitation details, patch, or PoC.

    02012300
    1.1K followersView on X
  • Security Art Work@Securityartwork

    ¡¡Nuevo post en nuestro blog!! De lectura de archivos a ejecución remota de comandos en Windmill – Encadenando vulnerabilidades https://www.securityartwork.es/2026/09/28/windmill-cve-2026-29059-cve-2026-22683-rce/ Enjoy :)

    00001500
    16.5K followersView on X
  • T1erOne@tieroneforum

    Цепочка эксплуатации Windmill: от path traversal до RCE через утечку SUPERADMIN_SECRET (CVE-2026-29059, CVE-2026-22683) https://tier1.life/thread/665 https://tieronemkfevyizxcnt355agysp2iemvhon6iyclwrc7yuc7oszgzrid.onion/thread/665 #articles #RCE #CVE #CyberSecurity @s2grupo

    00000128
    332 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Windmill: disponibile #PoC per lo sfruttamento delle CVE-2026-23696 e CVE-2026-22683 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/windmill-disponibile-un-poc-per-lo-sfruttamento-delle-cve-2026-23696-e-cve-2026-22683 ⚠️ Importante aggiornare i software interessati https://t.co/Vcvv5QasLs

    Post summary

    A PoC for CVE‑2026‑23696 and CVE‑2026‑22683, both RCE, is available via a link and users are urged to update affected software.

    00000133
    605 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Windmill: un disponibile #PoC per lo sfruttamento delle CVE-2026-23696 e CVE-2026-22683 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/windmill-un-disponibile-poc-per-lo-sfruttamento-delle-cve-2026-23696-e-cve-2026-22683 ⚠️ Importante aggiornare i software interessati https://x.com/csirt_it/status/2041887758763921772/photo/1

    Post summary

    A PoC is available for CVE-2026-23696 and CVE-2026-22683, exposing a Remote Code Execution risk; users are urged to update affected software.

    0000062
    605 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22683: HIGH] Windmill versions 1.56.0 through 1.614.0 have a critical vulnerability enabling Operators to create or modify entities. This poses a severe cyber security risk.#cve,CVE-2026-22683,#cybersecurity https://cvefind.com/CVE-2026-22683

    Post summary

    The tweet announces CVE‑2026‑22683, a high‑severity flaw in Windmill 1.56.0–1.614.0 that permits operators to create or modify entities, highlighting a significant security risk.

    0000027
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22683 Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation … https://www.cve.org/CVERecord?id=CVE-2026-22683

    Post summary

    The post announces CVE-2026-22683, a missing authorization flaw in Windmill that lets Operator-role users create prohibited entities; no PoC, exploit, or patch details are provided.

    00000128
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appnextcloudflow---
Appwindmillwindmill---

Explore more