Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
ID: d7ce530b-0fc4-50d8-85f4-6137a9d17a85
STIX ID: report--d7ce530b-0fc4-50d8-85f4-6137a9d17a85
Feed Name: The Hacker News
A high-severity path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in Windmill's get_log_file endpoint has been exploited in the wild to read sensitive files (e.g., /etc/passwd and potentially /proc/1/environ to retrieve SUPERADMIN_SECRET). VulnCheck observed exploitation against exposed Windmill instances (~170 systems) and researchers report broad active exploitation across several recent critical flaws—additionally, WordPress 'wp2shell' and other CVEs have been added to CISA's KEV catalog, with multiple PoCs and in-the-wild attempts that include commands to exfiltrate credentials, download malware, and achieve remote code execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
