Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Coca Cola Reveals Subsidiary Fairlife Suffered Data Breach

July 29, 2026

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

July 29, 2026

Microsoft Launches Flurry of AI Security Initiatives

July 28, 2026
Facebook X (Twitter) Instagram
Wednesday, July 29
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
News

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

Team-CWDBy Team-CWDJuly 29, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).

“The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences,” according to an advisory published by Windmill in March 2026.

“The primary sensitive value exposed by this vulnerability is the SUPERADMIN_SECRET environment variable, readable via /proc/1/environ. When set, this secret can be used as a Bearer token to authenticate as a superadmin and execute arbitrary code through the job preview API.”

However, it’s worth noting that SUPERADMIN_SECRET is not set by default, and for standalone Windmill instances without SUPERADMIN_SECRET configured, the impact of the vulnerability is limited to arbitrary file read. The issue has since been addressed in Windmill 1.603.3, released in January 2026, by adding sanitization checks to the filename parameter to prevent directory traversal.

According to VulnCheck, whose security researcher Valentin Lobstein is credited with discovering and reporting the flaw, exploitation efforts have been directed against Windmill’s “get_log_file” endpoint to extract sensitive information from the “/etc/passwd” file.

“We’ve observed exploits aimed at both direct Windmill endpoints and the Nextcloud proxy path,” Caitlin Condon, vice president of security research at VulnCheck, said in a post on LinkedIn.

The cybersecurity company said it identified about 170 vulnerable systems exposed across 24 countries.

The disclosure comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, including two WordPress bugs tracked as wp2shell (CVE-2026-60137 and CVE-2026-63030), along with a stack-based buffer overflow in DD-WRT (CVE-2021-27137) and an unauthenticated remote code execution issue in Langflow (CVE-2026-0770).

“wp2shell is one of the most significant WordPress Core security events in recent years,” Wordfence said. “The combination of unauthenticated reachability, no plugin or theme requirement, a large global attack surface, a path to administrator access and code execution, as well as public proof-of-concept exploit availability makes this vulnerability chain unusually serious.”

Attack data captured by the WordPress security company shows that threat actors are issuing requests to exploit the REST API batch request route-confusion issue and an unauthenticated SQL injection to achieve code execution.

VulnCheck also said it had verified more than two-dozen unique PoC exploits targeting WP2Shell as of July 19, 2026. “Affected users should update to a fixed version of WordPress as soon as possible, given the overwhelming likelihood that various public exploits and large-scale exploitation will follow the high-profile disclosure,” it added.

As for CVE-2026-0770, KEVIntel’s Ryan Dewhurst told The Hacker News that first in-the-wild attack efforts targeting the flaw were detected against its sensors on June 27, 2026, recording 137 exploitation attempts from 46 unique attacker IP addresses associated with 17 countries since then.

No less than 75 attempts, which account for more than half of the activity, originated from 20 attacker IP addresses during the last seven days. Observed payloads include base command execution checks, attempts to extract the contents of “/etc/passwd” or access AWS credentials, environment variable collection, malware downloads using wget or curl, and shell script execution to install second-stage payloads.

“The activity is not limited to vulnerability checks,” Dewhurst said. “While much of it involved commands such as id, whoami and reading /etc/passwd, we also observed payloads attempting to download malware and obtain environment variables, AWS credentials and container metadata.”

Federal Civilian Executive Branch (FCEB) agencies are advised to remediate the identified flaws by July 24, 2026.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Launches Flurry of AI Security Initiatives
Next Article Coca Cola Reveals Subsidiary Fairlife Suffered Data Breach
Team-CWD
  • Website

Related Posts

News

Coca Cola Reveals Subsidiary Fairlife Suffered Data Breach

July 29, 2026
News

Microsoft Launches Flurry of AI Security Initiatives

July 28, 2026
News

The Fastest Path to AI Adoption Runs Through Security

July 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A phishing attack that doesn’t steal your password

June 15, 2026

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Is it OK to let your children post selfies online?

February 17, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.