CVE-2026-23696Disclosure

MEDIUMCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-07); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-04-07: 4Mentions · 2026-04-08: 3Mentions · 2026-07-23: 1PoC Mentioned / Linked · 2026-04-08: 2PoC Mentioned / Linked · 2026-07-23: 1Exploit Tool / Code · 2026-04-08: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 2Technical Details · 2026-04-07: 4Technical Details · 2026-04-08: 3Technical Details · 2026-07-23: 104-0704-0807-23
Signal classification3 categories
Disclosure
450.0%
PoC
337.5%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-074
Disclosure3Patch1
2026-04-083
Disclosure1PoC2
2026-07-231
PoC1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-23696 - critical 🚨 Windmill < 1.603.3 - SQL Injection > Windmill versions 1.276.0 through 1.603.2 contain an authenticated SQL injection vuln... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-23696 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post discloses an authenticated SQL injection flaw in Windmill versions prior to 1.603.3 and provides a link to a library entry that likely contains proof‑of‑concept code.

    00012231
    1.1K followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-39337 | CVSS 10.0 🔴 CVE-2026-39933 | CVSS 10.0 🔴 CVE-2026-23696 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet announces three newly disclosed CVEs with their CVSS scores and provides a link to a vulnerabilities page, but gives no further technical depth or exploit information.

    0001080
    5.6K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-23696 — CVSS 9.9/10 ██████████ Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/dmkaLTZqdD

    Post summary

    The tweet announces a critical SQL injection CVE-2026-23696 affecting Windmill CE and EE versions 1.276.0–1.603.2 and urges users to apply the available patch immediately.

    1000033
    16 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Windmill: disponibile #PoC per lo sfruttamento delle CVE-2026-23696 e CVE-2026-22683 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/windmill-disponibile-un-poc-per-lo-sfruttamento-delle-cve-2026-23696-e-cve-2026-22683 ⚠️ Importante aggiornare i software interessati https://t.co/Vcvv5QasLs

    Post summary

    Windmill vulnerabilities CVE‑2026‑23696 and CVE‑2026‑22683 have a PoC available and links to it, but only a general recommendation to update affected software is provided; no active exploitation or detailed exploit code is mentioned.

    00000133
    605 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Windmill: un disponibile #PoC per lo sfruttamento delle CVE-2026-23696 e CVE-2026-22683 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/windmill-un-disponibile-poc-per-lo-sfruttamento-delle-cve-2026-23696-e-cve-2026-22683 ⚠️ Importante aggiornare i software interessati https://x.com/csirt_it/status/2041887758763921772/photo/1

    Post summary

    The post announces a PoC for CVE‑2026‑23696 and CVE‑2026‑22683 and urges users to update affected software.

    0000062
    605 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-23696: CRITICAL] Windmill CE/EE versions 1.276.0-1.603.2 have an SQL injection flaw in folder ownership management. Attackers can access sensitive data and execute arbitrary code.#cve,CVE-2026-23696,#cybersecurity https://cvefind.com/CVE-2026-23696

    Post summary

    Windmill CE/EE versions 1.276.0–1.603.2 are vulnerable to a critical SQL injection that could enable attackers to read sensitive data and execute arbitrary code. No PoC, exploit, or patch details are shared.

    0000029
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23696 Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated … https://www.cve.org/CVERecord?id=CVE-2026-23696

    Post summary

    The post announces an SQL injection vulnerability in Windmill CE and EE versions 1.276.0 through 1.603.2 that allows authenticated users to manipulate folder ownership management.

    00000115
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23696: Wind... Folder ownership SQLi leaks JWT secrets enabling admin token forgery → RCE through workflow endpoints - classic auth bypass chain. #SQLi #RCE #JWT. https://zerodaysignal.com/vulnerability/CVE-2026-23696 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑23696, outlines a SQL injection that leaks JWT secrets leading to RCE, but provides no PoC, exploit tool, patch, or evidence of active exploitation.

    0000071
    204 followersView on X

Explore more