
Windfall - Unauth RCE in Windmill & Nextcloud Flow (CVE-2026-29059) Path traversal to credential leak to root shell. No authentication required on any deployment type, including behind Nextcloud's proxy. Metasploit modules + full toolkit included. Also publishing a new technique for dumping PostgreSQL databases by reading heap files from disk. If you have filesystem access as root, you can extract every table without credentials or SQL access. Full binary parser with JSONB support. Write-up: https://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/ PG heap dump technique: https://chocapikk.com/posts/2026/dumping-postgresql-without-credentials/ PG heap dump tool: https://github.com/Chocapikk/pgread Exploit toolkit + labs: https://github.com/Chocapikk/Windfall
Post summary
The notice describes an unauthenticated RCE in Windmill/Nextcloud Flow (CVE‑2026‑29059) and supplies Metasploit modules, a full exploit toolkit, and a new PostgreSQL heap dump technique, indicating ready‑to‑use exploitation capabilities.















