Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
VulnCheck says CVE-2026-29059 in Windmill is being actively exploited to abuse the get_log_file endpoint for arbitrary file reads, with attackers trying to access sensitive data such as /etc/passwd and, in some cases, SUPERADMIN_SECRET. CISA has also added multiple flaws to its KEV catalog, while exploitation activity is surging against WordPress wp2shell and Langflow CVE-2026-0770. #Windmill #CVE-2026-29059 #wp2shell #CVE-2026-0770 #CISA

Keypoints

  • CVE-2026-29059 affects Windmill’s get_log_file endpoint with unauthenticated path traversal.
  • Attackers are using ../ sequences to read arbitrary files on vulnerable systems.
  • SUPERADMIN_SECRET exposure could enable superadmin access and code execution.
  • VulnCheck found about 170 vulnerable Windmill systems exposed across 24 countries.
  • CISA added Windmill-adjacent active threats, including wp2shell, DD-WRT CVE-2021-27137, and Langflow CVE-2026-0770, to its KEV catalog.

Read More: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html