Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
CYBERSECURITY FEATURED ANALYSIS

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

BY

The Hacker News

SOURCE

The Hacker News

DATE

READ

1 min read

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of …

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}"). “The filename parameter is concatenated into