Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
The Hacker News
3 weeks ago

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

By info@thehackernews.com (The Hacker News)

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}"). "The filename parameter is concatenated into

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.