What is CVE-2026-72542?
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in a workspace, regardless of ownership. The issue stems from job_metrics handlers accepting no authorization extractor, bypassing workspace-level access controls.
Azərbaycanca: Windmill Labs Windmill 1.783.0 versiyasına qədər olan sistemlərdə autentifikasiya çatışmazlığı zəifliyi aşkar edilib. Bu, hər hansı bir authenticated operatora workspace daxilində sahibliyindən asılı olmayaraq işlərin gedişatını yazmağa və job metrics oxumağa imkan verir — bunun səbəbi job_metrics handler-lərinin heç bir authorization ekstraktoru qəbul etməməsidir. Dərhal sistem yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Windmill Labs
FAQ2
Which versions of Windmill are affected by CVE-2026-72542?
All versions of Windmill Labs Windmill through 1.783.0 are affected by this missing authorization vulnerability.
What is the root cause of this vulnerability?
The root cause is that the job_metrics handlers accept no authorization extractor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.