← All stories
● Covered by 1 source · 1 reportHigh impact

Windmill Security Flaw Exploited to Access Sensitive Server Files

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

A high-severity security vulnerability (CVE-2026-29059) in Windmill allows unauthenticated attackers to read arbitrary server files. The flaw, related to path traversal in the 'get_log_file' endpoint, has been actively exploited, exposing sensitive information across 170 vulnerable systems worldwide.

Key points

  • Vulnerability CVE-2026-29059 has a CVSS score of 7.5
  • Allows attackers to read files using path traversal
  • Exploited in the wild across 170 systems in 24 countries

Vulnerability Details

The vulnerability identified as CVE-2026-29059 affects Windmill's 'get_log_file' endpoint, enabling unauthenticated path traversal. Attackers can manipulate the filename parameter to access arbitrary files on the server.

Sensitive Information Exposure

The primary sensitive data at risk is the SUPERADMIN_SECRET environment variable. If this variable is compromised, it can grant attackers superadmin access, allowing for arbitrary code execution via the job preview API. However, the SUPERADMIN_SECRET is not set by default for standalone instances, limiting potential impact.

Impact and Exploitation

Exploitation attempts have targeted the 'get_log_file' endpoint to extract sensitive files, including '/etc/passwd'. VulnCheck observed these exploits on direct Windmill endpoints and through a Nextcloud proxy.

Response and Remediation

Windmill addressed this vulnerability in version 1.603.3, released in January 2026, by implementing sanitization checks for the filename parameter. This update aims to close the path traversal method of attack.

Broader Cybersecurity Context

The discovery of this vulnerability coincides with other significant vulnerabilities being documented in the U.S. CISA's Known Exploited Vulnerabilities catalog. This highlights ongoing risks within widely used software frameworks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 35 stories · Jul 22

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A high-severity security vulnerability (CVE-2026-29059) in Windmill allows unauthenticated attackers to read arbitrary server files. The flaw, related to path traversal in the 'get_log_file' endpoint, has been actively exploited, exposing sensitive information across 170 vulnerable systems worldwide.