CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3013

As cited

Copy frozen at (site build).

vulnerabilities

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in open-source developer platform Windmill allows attackers to read arbitrary server files without authentication through the get_log_file endpoint. The flaw has entered active exploitation in the wild.

Why it matters: Organizations running Windmill deployments face immediate risk of unauthorized data access and should patch or mitigate this unauthenticated endpoint without delay.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

CVE-2026-29059, an unauthenticated path traversal flaw in Windmill's get_log_file endpoint, allows remote attackers to read arbitrary server files without credentials. The vulnerability carries a CVSS score of 6.9 and is actively exploited in the wild according to VulnCheck.

Why it matters: Organizations running Windmill must immediately audit access logs and patch this endpoint, as unauthenticated file read attacks expose sensitive configuration, credentials, and application data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

CVE-2026-29059, an unauthenticated path traversal flaw in Windmill's get_log_file endpoint, allows remote attackers to read arbitrary server files without credentials. The vulnerability carries a CVSS score of 6.9 and is actively exploited in the wild according to VulnCheck.

Why it matters: Organizations running Windmill must immediately audit access logs and patch this endpoint, as unauthenticated file read attacks expose sensitive configuration, credentials, and application data.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary