CVE-2026-29059

Confirmed PUBLISHED

Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly

windmill-labs · windmill

Not yet in CISA KEV

Exploited in the wild Active exploitation observed PoC available

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
16
Unique Attacker IPs
2
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
6.9 Medium EPSS 2.6%

At a Glance

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences. This issue has been patched in version 1.603.3.

CVE Published
Mar 06, 2026
Exploited Since
Jul 03, 2026
CVSS
6.9 Medium
EPSS
2.6%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
windmill-labs
windmill

< 1.603.3

Affected

CVE References

Recommended Actions

  • Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.
  • Review sensor telemetry for request paths, attacker IPs, and payload patterns that may inform detection and exposure validation.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.