Hackers Exploit Windmill CVE-2026-29059 on 170 Systems Across 24 Countries
Updated
Updated · The Hacker News · Jul 22
Hackers Exploit Windmill CVE-2026-29059 on 170 Systems Across 24 Countries
3 articles · Updated · The Hacker News · Jul 22
Summary
VulnCheck said attackers are actively abusing Windmill flaw CVE-2026-29059 to read arbitrary server files through the get_log_file endpoint, with observed attempts pulling data from /etc/passwd.
The CVSS 7.5 bug stems from an unsanitized filename parameter that allows unauthenticated path traversal; if SUPERADMIN_SECRET is configured, attackers can steal it from /proc/1/environ and use it for superadmin access and code execution.
Windmill fixed the issue in version 1.603.3 by sanitizing the filename input, but VulnCheck still found about 170 exposed vulnerable systems and said attacks also hit the Nextcloud proxy path.
The disclosure landed as CISA added four flaws to its Known Exploited Vulnerabilities catalog, including two WordPress wp2shell bugs, DD-WRT CVE-2021-27137 and Langflow CVE-2026-0770, with FCEB agencies ordered to patch by July 24.