What is CVE-2026-29059?
A high-severity unauthenticated path traversal vulnerability in the open-source Windmill platform is being actively exploited, allowing attackers to read arbitrary server files via the "get_log_file" endpoint. Users are strongly advised to immediately update Windmill to the latest patched version.
Azərbaycanca: Windmill açıq mənbəli tərtibatçı platformasında autentifikasiya olmadan ixtiyari server fayllarının oxunmasına imkan verən yüksək səviyyəli "path traversal" zəifliyi aktiv şəkildə istismar edilir. "get_log_file" endpoint-i vasitəsilə hücum edilir. İstifadəçilər təcili olaraq Windmill-i ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What threat does the actively exploited CVE-2026-29059 pose in the Windmill platform?
CVE-2026-29059 is a high-severity unauthenticated path traversal vulnerability that allows reading arbitrary server files.
What should Windmill users do to protect against CVE-2026-29059?
Users should immediately update Windmill to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.