256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication - The Hacker News

Share
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication - The Hacker News
Image · Internet

What the report says

The Hacker News reported on July 22, 2026, that attackers are actively exploiting a high-severity vulnerability in Windmill, an open-source developer platform used to build internal tools and workflows. The flaw, tracked as CVE-2026-29059 with a CVSS score of 7.5, is an unauthenticated path traversal issue affecting Windmill’s get_log_file API endpoint. VulnCheck said roughly 170 exposed vulnerable systems were found across 24 countries.

According to the article, the bug allows an attacker to manipulate the filename parameter with directory traversal sequences and read files from the server without logging in. Windmill’s advisory said the most sensitive exposure could involve the SUPERADMIN_SECRET environment variable, which, if configured, may allow superadmin authentication and further code execution through a job preview API. The article notes that this secret is not enabled by default, meaning some standalone deployments may be limited to arbitrary file read.

VulnCheck, whose researcher Valentin Lobstein was credited with discovering and reporting the flaw, said exploitation has targeted the endpoint to retrieve sensitive files such as /etc/passwd. VulnCheck’s Caitlin Condon also said activity was seen against both direct Windmill endpoints and a Nextcloud proxy path. The issue was fixed in Windmill 1.603.3 through filename sanitization checks.

The report also placed the Windmill activity in a broader wave of exploitation, noting that CISA added several other actively exploited flaws to its Known Exploited Vulnerabilities catalog, including WordPress, DD-WRT and Langflow issues. For affected Windmill operators, the key action is to update to a fixed version and review exposed instances for suspicious file-read attempts.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting