logo

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

ID: d7ce530b-0fc4-50d8-85f4-6137a9d17a85

STIX ID: report--d7ce530b-0fc4-50d8-85f4-6137a9d17a85

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: [email protected] (The Hacker News)

...
...

A high-severity path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in Windmill's get_log_file endpoint has been exploited in the wild to read sensitive files (e.g., /etc/passwd and potentially /proc/1/environ to retrieve SUPERADMIN_SECRET). VulnCheck observed exploitation against exposed Windmill instances (~170 systems) and researchers report broad active exploitation across several recent critical flaws—additionally, WordPress 'wp2shell' and other CVEs have been added to CISA's KEV catalog, with multiple PoCs and in-the-wild attempts that include commands to exfiltrate credentials, download malware, and achieve remote code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.