CVE-2026-29059: Unauthenticated Path Traversal in Windmill Allows Arbitrary File Access
A high-severity path traversal vulnerability (CVE-2026-29059) in Windmill's 'get_log_file' endpoint allows unauthenticated attackers to read arbitrary server files, including sensitive environment variables like SUPERADMIN_SECRET, which could enable superadmin access and code execution. The flaw was patched in version 1.603.3 but remains active in exploited systems worldwide.
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}").
"The filename parameter is concatenated into
*** END OF TRANSMISSION ***