What is CVE-2026-72539?
This vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts containing plaintext credentials. Immediate upgrade and cleanup of old drafts are recommended.
Azərbaycanca: Bu boşluq Windmill avtomatlaşdırma platformasında autentifikasiya olunmuş istənilən istifadəçiyə sahibsiz qaralama skriptlərdəki resurs etimadnamələrini oxumağa imkan verir. Təsirə məruz qalan versiyalar 1.783.0-a qədərdir. Təcili olaraq ən son versiyaya yeniləmə və köhnə qaralamaları təmizləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of data can be exposed through the CVE-2026-72539 vulnerability in Windmill?
The vulnerability allows any authenticated workspace member to read plaintext credentials stored in legacy ownerless draft scripts.
What measures are recommended to mitigate CVE-2026-72539?
Immediate upgrade from affected versions (through 1.783.0) to the latest version and cleanup of old ownerless drafts are recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.