Security
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
The Hacker News·July 22, 2026·1 min read
A high-severity security flaw in open-source platform Windmill, CVE-2026-29059 with a CVSS score of 7.5, is under active exploitation. The unauthenticated path traversal vulnerability affects Windmill's get_log_file endpoint, where the filename parameter is concatenated into the path, allowing attackers to read arbitrary server files without authentication, per VulnCheck.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
