CVE-2026-29059Active Exploitation(windmill / windmill)

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch windmill windmill systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences. This issue has been patched in version 1.603.3.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windmill

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 11 observed days

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 17 signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 7 mentions (2026-07-22); latest day: 1
  • 23 total mentions across 11 days

Affected systems

Vendors
Products
windmill

Deep dive

Activity timeline23 mentions / 11d
02457Mentions · 2026-03-06: 2Mentions · 2026-04-07: 2Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Mentions · 2026-07-21: 2Mentions · 2026-07-22: 7Mentions · 2026-07-23: 1Mentions · 2026-07-24: 4Mentions · 2026-07-28: 1Mentions · 2026-09-28: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-04-07: 2PoC Mentioned / Linked · 2026-04-14: 1Exploit Tool / Code · 2026-04-07: 2Active Exploitation · 2026-07-21: 2Active Exploitation · 2026-07-22: 5Active Exploitation · 2026-07-23: 1Active Exploitation · 2026-07-24: 4Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-07-22: 1Patch / Workaround · 2026-07-24: 1Patch / Workaround · 2026-07-28: 1Technical Details · 2026-03-06: 2Technical Details · 2026-04-07: 2Technical Details · 2026-04-14: 1Technical Details · 2026-07-21: 2Technical Details · 2026-07-22: 7Technical Details · 2026-07-23: 1Technical Details · 2026-07-24: 1Technical Details · 2026-07-28: 103-0604-0704-1404-1607-2107-2207-2307-2407-2809-2810-06
Signal classification5 categories
Active Exploitation
1361.9%
Disclosure
314.3%
Patch
29.5%
Exploit
29.5%
PoC
14.8%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure1Patch1
2026-04-072
Exploit2
2026-04-141
PoC1
2026-04-161
Disclosure1
2026-07-212
Active Exploitation2
2026-07-227
Active Exploitation5Disclosure1Patch1
2026-07-231
Active Exploitation1
2026-07-244
Active Exploitation4
2026-07-281
Active Exploitation1
Full discourse20 posts
  • Chocapikk@Chocapikk_
    Exploit

    Windfall - Unauth RCE in Windmill & Nextcloud Flow (CVE-2026-29059) Path traversal to credential leak to root shell. No authentication required on any deployment type, including behind Nextcloud's proxy. Metasploit modules + full toolkit included. Also publishing a new technique for dumping PostgreSQL databases by reading heap files from disk. If you have filesystem access as root, you can extract every table without credentials or SQL access. Full binary parser with JSONB support. Write-up: https://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/ PG heap dump technique: https://chocapikk.com/posts/2026/dumping-postgresql-without-credentials/ PG heap dump tool: https://github.com/Chocapikk/pgread Exploit toolkit + labs: https://github.com/Chocapikk/Windfall

    Post summary

    The notice describes an unauthenticated RCE in Windmill/Nextcloud Flow (CVE‑2026‑29059) and supplies Metasploit modules, a full exploit toolkit, and a new PostgreSQL heap dump technique, indicating ready‑to‑use exploitation capabilities.

    25201597719.2K
    4.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    Windmill servers are under active attack. Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution. Full details: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html

    Post summary

    CVE‑2026‑29059 is being actively exploited on Windmill servers, enabling attackers to read arbitrary files, gain superadmin privileges, and execute code, as detailed in the linked article.

    4190502029.3K
    2.3M followersView on X
  • blueblue@piedpiper1616
    Exploit

    GitHub - Chocapikk/Windfall: Windfall - Unauthenticated RCE exploit chain for Windmill & Nextcloud Flow (CVE-2026-29059). Path traversal + credential leak + PostgreSQL heap dump + Nextcloud AppAPI takeover. · GitHub - https://github.com/Chocapikk/Windfall

    Post summary

    The GitHub repository demonstrates an unauthenticated RCE exploit chain for CVE-2026-29059, detailing a series of steps including path traversal, credential leakage, and service takeover.

    07027152.2K
    5.5K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    New KEV: CVE-2026-29059 is an unauth path traversal @Chocapikk_ discovered in the popular Windmill automation platform. @VulnCheckAI Canaries seeing a handful of exploits hit both direct Windmill endpoints + the NextCloud proxy path. More KEVs (free): https://www.vulncheck.com/kev

    Post summary

    CVE‑2026‑29059 is a known exploitable path traversal flaw in Windmill, confirmed being actively leveraged against both direct endpoints and the NextCloud proxy.

    0412254.0K
    3.6K followersView on X
  • ʞʞıdɐɔoɥƆ@Chocapikk_
    Active Exploitation

    CVE-2026-29059 just hit the KEV. Unauth path traversal in Windmill, but through Nextcloud Flow it chains into file read + RCE as root in the container + privesc to Nextcloud admin via AppAPI.

    Post summary

    CVE-2026-29059 was added to the KEV, indicating it is being exploited in the wild. The vulnerability is an unauthenticated path traversal in Windmill that can be chained to read files, execute code as root in the container, and further elevate privileges to Nextcloud admin via AppAPI.

    0401232.1K
    4.1K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Nextcloud ❗ CVE-2026-29059 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-nextcloud/ https://t.co/BcookJhFZL

    Post summary

    The tweet announces CVE‑2026‑29059 as a vulnerability in Nextcloud products and directs readers to a link for additional information, but it does not provide technical details, exploit code, or patch information.

    0003074
    6.7K followersView on X
  • Halil Deniz@denizhalilT
    Disclosure

    🚨 Critical Security Advisory: CVE-2026-29059! Unauthenticated Path Traversal vulnerability found in Windmill & Nextcloud Flow (<1.603.3). Attackers can read sensitive files & escalate privileges. https://denizhalil.com/2026/07/23/cve-2026-29059-windmill-path-traversal/ #CVE202629059 #CyberSecurity #Windmill https://t.co/3muBQ4JhLr

    Post summary

    The tweet announces a newly disclosed unauthenticated path traversal vulnerability in Windmill and Nextcloud Flow (<1.603.3) that permits file read and privilege escalation, but it does not provide PoC, exploit code, or patch details.

    0101061
    32 followersView on X
  • Security Art Work@Securityartwork

    ¡¡Nuevo post en nuestro blog!! De lectura de archivos a ejecución remota de comandos en Windmill – Encadenando vulnerabilidades https://www.securityartwork.es/2026/09/28/windmill-cve-2026-29059-cve-2026-22683-rce/ Enjoy :)

    00001500
    16.5K followersView on X
  • CyberTLDR@CyberTLDR
    Active Exploitation

    1/3 Attackers are actively exploiting a Windmill flaw to read any file on the server with no login. CVE-2026-29059 (CVSS 7.5) is unauthenticated path traversal that can leak the admin secret and lead to code execution. Are you exposed? #CyberSecurity #InfoSec #CVE #TechNews https://t.co/bIDYpvv5Ex

    Post summary

    Attackers are actively exploiting CVE-2026-29059—a path traversal flaw in Windmill that allows unauthenticated file read and may lead to code execution.

    1000054
    33 followersView on X
  • iototsecnews@iototsecnews
    PoC

    Windmill の脆弱性 CVE-2026-29059 が FIX:エクスプロイト・フレームワーク Windfall も登場 https://iototsecnews.jp/2026/04/07/windmill-developer-platform-flaws-expose-users-to-rce-attacks-proof-of-concept-published/ この脆弱性の原因は、Windmill プラットフォームのログ取得エンドポイントにおける、ファイルパスの不十分なサニタイズ処理にあります。この不備により、CVE-2026-29059 という最大深刻度 10.0 のパス トラバーサル脆弱性が生じ、未認証の第三者がシステム内の機密ファイルを自由に読み取れる状態になっていました。さらに、Nextcloud Flow との統合におけるミスコンフィグや SQL インジェクションの脆弱性が重なったことで、認証回避が引き起こされ、管理者権限の奪取やデータベースの抽出が容易になってしまいます。ご利用のチームは、ご注意ください。 #CVE202629059 #Vulnerability #Windmill

    Post summary

    Windmill’s CVE‑2026‑29059 is a path‑traversal flaw with an available proof‑of‑concept; it enables unauthenticated file reads and can lead to admin escalation when combined with misconfigurations, but no active exploitation or patch information is reported.

    01000114
    484 followersView on X
  • T1erOne@tieroneforum

    Цепочка эксплуатации Windmill: от path traversal до RCE через утечку SUPERADMIN_SECRET (CVE-2026-29059, CVE-2026-22683) https://tier1.life/thread/665 https://tieronemkfevyizxcnt355agysp2iemvhon6iyclwrc7yuc7oszgzrid.onion/thread/665 #articles #RCE #CVE #CyberSecurity @s2grupo

    00000128
    332 followersView on X
  • BT Haberler@BTHaberler
    Active Exploitation

    Windmill / Kimlik Doğrulamasız Dosya Okuma Açığı 170 sistem 24 ülkede aktif saldırı altında: Windmill platformunda kimlik doğrulaması gerektirmeyen dosya okuma açığı! VulnCheck'ten Valentin Lobstein, açık kaynak geliştirici platformu Windmill'de CVE-2026-29059'u (CVSS 7.5) keşfetti. get_log_file endpoint'i, filename parametresini düzgün temizlemiyor, bu da "../" dizin geçiş dizileriyle sunucudaki keyfi dosyaların okunmasına izin veriyor. • Saldırganlar /etc/passwd gibi hassas dosyaları hedef alıyor; kimlik doğrulaması gerekmiyor. • SUPERADMIN_SECRET ortam değişkeni yapılandırılmışsa /proc/1/environ üzerinden ifşa olabiliyor; bu da superadmin bearer token'ı olarak iş önizleme API'siyle keyfi kod çalıştırmaya izin veriyor. • Yama Ocak 2026'da 1.603.3 sürümüyle geldi; aktif istismar doğrulandı, 24 ülkede ~170 savunmasız sistem tespit edildi. Windmill kullanıyorsanız hemen güncelleyin ve SUPERADMIN_SECRET'i mutlaka ayarlı tutmayın veya sıkı korumaya alın! #SiberGüvenlik #Windmill #GüvenlikAçığı

    Post summary

    Windmill’s CVE-2026-29059, a directory traversal file‑read flaw, is actively exploited on over 170 systems in 24 countries; a patch (v1.603.3) was released in January 2026.

    0000049
    38 followersView on X
  • Carlos Fynn@fynn_JourX
    Active Exploitation

    Windmill CVE-2026-29059 turns log access into a… is the kind of management-plane bug defenders should move on fast. It combines active exploitation with credential theft and auth bypass risk in FortiClient EMS. When endpoint management infrastructure is exposed, the bl…

    Post summary

    CVE‑2026‑29059 is actively exploited in FortiClient EMS, enabling credential theft and authentication bypass as its primary impact.

    0000037
    85 followersView on X
  • Carlos Fynn@fynn_JourX
    Active Exploitation

    Legacy exposure keeps paying off for attackers. Windmill CVE-2026-29059 turns log access into a secrets p… Attackers are exploiting Windmill CVE-2026-29059 to read files from exposed servers, raisin… 🔗 Read → https://invaders.ie/resources/blog/vulnerability/windmill-cve-2026-29059-active-exploitation-secrets-risk

    Post summary

    The post indicates that Windmill CVE-2026-29059 is being exploited in the wild to read files from exposed servers, but it does not provide proof of concept, exploit code, or technical details about the vulnerability.

    0000037
    85 followersView on X
  • Lucas@lucasverdan
    Active Exploitation

    Windmill CVE-2026-29059 turns log access into a… is already being exploited, and Fortinet says the FortiClient EMS flaw carries credential theft and auth bypass risk. If you run 7.4.5 or 7.4.6, treat it as exposed management-plane risk and hotfix now.

    Post summary

    CVE-2026-29059 is reported as actively exploited, leading to credential theft and authentication bypass, and vendors recommend applying hotfixes for affected FortiClient versions.

    0000058
    308 followersView on X
  • Lucas@lucasverdan
    Active Exploitation

    🛑 Windmill CVE-2026-29059 turns log access into a secrets problem Attackers are exploiting Windmill CVE-2026-29059 to read files from exposed servers, raisin… 🔗 Details → https://invaders.ie/resources/blog/vulnerability/windmill-cve-2026-29059-active-exploitation-secrets-risk

    Post summary

    The tweet announces that Windmill CVE‑2026‑29059 is currently being exploited to read arbitrary files from exposed servers, with no mention of patches or a PoC. The linked blog likely provides further technical details.

    0000046
    308 followersView on X
  • SecNews@SecNews_GR
    Active Exploitation

    CVE-2026-29059: κρίσιμη ευπάθεια path traversal στο Windmill αξιοποιείται ενεργά https://secn.ws/EmeiKb

    Post summary

    CVE-2026-29059, a path traversal flaw in Windmill, is currently being exploited in the wild.

    0000096
    7.0K followersView on X
  • SecNews@SecNews_GR
    Active Exploitation

    CVE-2026-29059: κρίσιμη ευπάθεια path traversal στο Windmill αξιοποιείται ενεργά https://secn.ws/vCIxZC

    Post summary

    The post reports CVE-2026-29059, a critical path traversal flaw in Windmill, as being actively exploited in the wild.

    0000083
    7.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-29059 to read arbitrary Windmill server files, then escalating to superadmin privileges for code execution. This path traversal-to-RCE chain demonstrates how file access vulnerabilities can enable full system compromise. Runtime segmentation helps limit blast radius when admin credentials are compromised. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/hackers-exploit-windmill-flaw-to-read-arbitrary-server-files-without-authentication

    Post summary

    The post reports that attackers are actively exploiting CVE‑2026‑29059 against Windmill servers, using a path‑traversal to RCE chain for privilege escalation, with runtime segmentation suggested as a mitigation.

    0000064
    1.9K followersView on X
  • The Clawd Lab | Cybersecurity News@TheClawdLab
    Patch

    Three mistakes turn an unauthenticated path-traversal flaw into a breach: 1) exposing Windmill to the internet; isolate it. 2) delaying CVE-2026-29059 remediation; patch now. 3) skipping log review; hunt get_log_file requests and unusual file reads. https://t.co/u7TrkNduuJ

    Post summary

    The tweet warns of an unauthenticated path‑traversal vulnerability (CVE‑2026‑29059) in Windmill, urging immediate isolation, patching, and log review for potential exploitation.

    00000108
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwindmillwindmill---

Explore more