Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-29059
CVE
CVE-2026-29059
View on NVD ↗
Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly
Exploitation IoCs
2
IP
20
IP
46
MITRE ATT&CK TTPs
5
T1059
Command and Scripting Interpreter
Execution
T1070.004
File Deletion
Defense Evasion
T1083
File and Directory Discovery
Discovery
T1105
Ingress Tool Transfer
Command And Control
T1135
Network Share Discovery
Discovery
Source Articles
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hackers are actively exploiting a high-severity unauthenticated path traversal vulnerability, CVE-2026-29059, in the open-source developer platform Windmill. The flaw exists in the 'get_log_file' endpoint, allowing attackers to read arbitrary files on the server by manipulating the filename parameter. A key target is the /proc/1/environ file to extract the SUPERADMIN_SECRET environment variable, which can enable superadmin authentication and arbitrary code execution if set. The vulnerability has been patched in Windmill 1.603.3, but exploitation attempts continue against exposed instances.
hacker-news
Jul 22, 2026