Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Microsoft is bringing original Xbox games to PC with backward compatibility

    July 22, 2026

    Amazon cuts jobs in AGI group as it puts more focus on customer-facing AI

    July 22, 2026

    JADEPUFFER and Autonomous Intrusion Operations: Why Enterprise XDR Architecture Must Evolve

    July 22, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
    Cybersecurity

    Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

    InfoForTechBy InfoForTechJuly 22, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ravie LakshmananJul 22, 2026Vulnerability / Web Security

    A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

    The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).

    “The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences,” according to an advisory published by Windmill in March 2026.

    “The primary sensitive value exposed by this vulnerability is the SUPERADMIN_SECRET environment variable, readable via /proc/1/environ. When set, this secret can be used as a Bearer token to authenticate as a superadmin and execute arbitrary code through the job preview API.”

    However, it’s worth noting that SUPERADMIN_SECRET is not set by default, and for standalone Windmill instances without SUPERADMIN_SECRET configured, the impact of the vulnerability is limited to arbitrary file read. The issue has since been addressed in Windmill 1.603.3, released in January 2026, by adding sanitization checks to the filename parameter to prevent directory traversal.

    According to VulnCheck, whose security researcher Valentin Lobstein is credited with discovering and reporting the flaw, exploitation efforts have been directed against Windmill’s “get_log_file” endpoint to extract sensitive information from the “/etc/passwd” file.

    “We’ve observed exploits aimed at both direct Windmill endpoints and the Nextcloud proxy path,” Caitlin Condon, vice president of security research at VulnCheck, said in a post on LinkedIn.

    The cybersecurity company said it identified about 170 vulnerable systems exposed across 24 countries.

    The disclosure comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, including two WordPress bugs tracked as wp2shell (CVE-2026-60137 and CVE-2026-63030), along with a stack-based buffer overflow in DD-WRT (CVE-2021-27137) and an unauthenticated remote code execution issue in Langflow (CVE-2026-0770).

    “wp2shell is one of the most significant WordPress Core security events in recent years,” Wordfence said. “The combination of unauthenticated reachability, no plugin or theme requirement, a large global attack surface, a path to administrator access and code execution, as well as public proof-of-concept exploit availability makes this vulnerability chain unusually serious.”

    Attack data captured by the WordPress security company shows that threat actors are issuing requests to exploit the REST API batch request route-confusion issue and an unauthenticated SQL injection to achieve code execution.

    As for CVE-2026-0770, KEVIntel’s Ryan Dewhurst told The Hacker News that it first detected exploitation attempts targeting the flaw against its sensors on June 27, 2026, recording 137 exploitation attempts from 46 unique attacker IP addresses associated with 17 countries.

    No less than 75 attempts, which account for more than half of the activity, originated from 20 attacker IP addresses during the last seven days. Observed payloads include base command execution checks, attempts to extract the contents of “/etc/passwd” or access AWS credentials, environment variable collection, malware downloads using wget or curl, and shell script execution to install second-stage payloads.

    “The activity is not limited to vulnerability checks,” Dewhurst said. “While much of it involved commands such as id, whoami and reading /etc/passwd, we also observed payloads attempting to download malware and obtain environment variables, AWS credentials and container metadata.”

    Federal Civilian Executive Branch (FCEB) agencies are advised to remediate the identified flaws by July 24, 2026.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    JADEPUFFER and Autonomous Intrusion Operations: Why Enterprise XDR Architecture Must Evolve

    July 22, 2026

    Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

    July 21, 2026

    Weekly Update 513: Clauding The Home Network

    July 21, 2026

    FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

    July 21, 2026

    Detect ARP Spoofing in Enterprise Networks

    July 20, 2026

    HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

    July 20, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.