Exploited in the wild Windmill platform web-app Windmill zero-day
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
CVE Tools coverage
A critical vulnerability in the open-source developer platform Windmill is being actively exploited in the wild, allowing attackers to read arbitrary server files without authentication. The flaw, tracked as CVE-2026-29059 (CVSS score: 7.5), affects the 'get_log_file' endpoint and enables path traversal attacks. Attackers can exploit this to access sensitive data like the SUPERADMIN_SECRET environment variable, which grants elevated privileges. A fix was released in version 1.603.3 in January 2026, but many systems remain vulnerable.