What is CVE-2026-72541?
A missing authorization vulnerability in Windmill Labs Windmill up to version 1.783.0 allows any authenticated workspace member to overwrite any resource type schema via the update_resource_type endpoint. The issue stems from a missing administrator permission check. Users are urged to upgrade to the latest version immediately.
Azərbaycanca: Windmill Labs Windmill-in 1.783.0-a qədər versiyalarında autentifikasiya olunmuş hər hansı bir iş sahəsi üzvünün update_resource_type endpoint-i vasitəsilə istənilən resurs tipi sxemini üzərinə yazmasına imkan verən nöqsan aşkarlanıb. Bu boşluq administrator icazəsi yoxlamasının olmaması səbəbilə yaranır. Mütəxəssislər dərhal ən son versiyaya yeniləməyi tövsiyə edir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Windmill Labs
FAQ2
Which versions of Windmill are affected by CVE-2026-72541?
The vulnerability affects Windmill Labs Windmill up to version 1.783.0.
What level of access does an attacker need to exploit CVE-2026-72541?
The attacker needs to be any authenticated workspace member, as the vulnerability stems from a missing administrator permission check.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.