type: cve ยท created: 2026-08-18 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: not-rated ยท affected_sectors: [] ยท au_impact: false
Windmill Path Traversal (CVE-2026-29059)
| Field | Value |
|---|---|
| CVE | CVE-2026-29059 |
| Type | Path Traversal โ Potential RCE |
| Status | Actively Exploited |
| CVSS | Not specified (high severity implied) |
| Disclosure | July 2026 |
| Affected | Windmill open-source platform |
Summary
An unauthenticated path traversal vulnerability in the open-source Windmill platform allows arbitrary file reads and potential remote code execution via SUPERADMIN_SECRET exposure.
Key Details
- Path traversal vulnerability enabling unauthenticated file reads
- Potential for RCE through exposure of SUPERADMIN_SECRET
- Active exploitation confirmed in the wild
- Windmill is an open-source workflow engine and platform
Significance
Active exploitation makes this a critical concern for organisations running self-hosted Windmill instances. The potential to escalate from file read to full RCE via secret exposure elevates the risk profile considerably.
Related Pages
- Cve 2026 50522 Sharepoint Server Rce โ Similarly exploited server-side vulnerability
- Cve 2026 6875 Servicenow Ai โ Another actively exploited platform vulnerability
Sources: The Hacker News (2026-07-22)