Back to all news
Security

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

The Hacker News·July 22, 2026·1 min read
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw in open-source platform Windmill, CVE-2026-29059 with a CVSS score of 7.5, is under active exploitation. The unauthenticated path traversal vulnerability affects Windmill's get_log_file endpoint, where the filename parameter is concatenated into the path, allowing attackers to read arbitrary server files without authentication, per VulnCheck.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store