Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication - The Hacker News

What the report says
The Hacker News reported on July 22, 2026, that attackers are actively exploiting a high-severity vulnerability in Windmill, an open-source developer platform used to build internal tools and workflows. The flaw, tracked as CVE-2026-29059 with a CVSS score of 7.5, is an unauthenticated path traversal issue affecting Windmill’s get_log_file API endpoint. VulnCheck said roughly 170 exposed vulnerable systems were found across 24 countries.
According to the article, the bug allows an attacker to manipulate the filename parameter with directory traversal sequences and read files from the server without logging in. Windmill’s advisory said the most sensitive exposure could involve the SUPERADMIN_SECRET environment variable, which, if configured, may allow superadmin authentication and further code execution through a job preview API. The article notes that this secret is not enabled by default, meaning some standalone deployments may be limited to arbitrary file read.
VulnCheck, whose researcher Valentin Lobstein was credited with discovering and reporting the flaw, said exploitation has targeted the endpoint to retrieve sensitive files such as /etc/passwd. VulnCheck’s Caitlin Condon also said activity was seen against both direct Windmill endpoints and a Nextcloud proxy path. The issue was fixed in Windmill 1.603.3 through filename sanitization checks.
The report also placed the Windmill activity in a broader wave of exploitation, noting that CISA added several other actively exploited flaws to its Known Exploited Vulnerabilities catalog, including WordPress, DD-WRT and Langflow issues. For affected Windmill operators, the key action is to update to a fixed version and review exposed instances for suspicious file-read attempts.
Loading debate for this article…
Other publishers covering this story
No additional verified coverage is currently clustered with this report.

AI platforms accelerating Uganda’s digital transformationThe Observer
Two MacBooks and an agent named BudThe Observer
La Fang Eco Resort hosts influencers to promote Dolwe Island tourismNile Post
How young is too young for AI?The Independent Uganda
Roku raises streaming stick prices by up to 60 percent - Ars TechnicaArs Technica
'See You in the Sequel': Halo 2 Remake All But Confirmed - Push SquarePush Square