Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-18 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: not-rated ยท affected_sectors: [] ยท au_impact: false

Windmill Path Traversal (CVE-2026-29059)

Field Value
CVE CVE-2026-29059
Type Path Traversal โ†’ Potential RCE
Status Actively Exploited
CVSS Not specified (high severity implied)
Disclosure July 2026
Affected Windmill open-source platform

Summary

An unauthenticated path traversal vulnerability in the open-source Windmill platform allows arbitrary file reads and potential remote code execution via SUPERADMIN_SECRET exposure.

Key Details

  • Path traversal vulnerability enabling unauthenticated file reads
  • Potential for RCE through exposure of SUPERADMIN_SECRET
  • Active exploitation confirmed in the wild
  • Windmill is an open-source workflow engine and platform

Significance

Active exploitation makes this a critical concern for organisations running self-hosted Windmill instances. The potential to escalate from file read to full RCE via secret exposure elevates the risk profile considerably.

Related Pages

Sources: The Hacker News (2026-07-22)