Tag

Cve 2026 29059

All articles tagged with #cve 2026 29059

Windmill path-traversal flaw exploited to read server files; patch issued
technology1 month ago

Windmill path-traversal flaw exploited to read server files; patch issued

A high-severity Windmill vulnerability, CVE-2026-29059, enables unauthenticated path traversal via the get_log_file endpoint to read arbitrary server files; if SUPERADMIN_SECRET is configured, the flaw could expose a Bearer-token for superadmin authentication and code execution, though default setups are limited to file reads. Windmill released a fix (1.603.3) in January 2026 by sanitizing the filename parameter. VulnCheck reports about 170 vulnerable systems across 24 countries and observed exploitation targeting Windmill endpoints and the Nextcloud proxy path. Separately, CISA’s KEV catalog highlights WP2Shell WordPress flaws and Langflow RCE vulnerabilities with widespread PoCs, urging WordPress users to update and noting a July 24, 2026 remediation deadline for Federal Civilian Executive Branch agencies.