The vulnerability known as CVE-2026-29059 in the Windmill platform arises due to insufficient input validation in the 'get_log_file' endpoint. Attackers can use ../ directory traversal sequences to read any file on the server. This method enables access to system files such as /etc/passwd, and if the SUPERADMIN_SECRET environment variable is set, attackers can gain superuser privileges.

The vulnerability was patched in Windmill version 1.603.3, with additional controls added to block directory traversal in the filename parameter. Security researchers have detected active exploitation of this flaw in approximately 170 systems across 24 countries. Exploitation attempts have been observed not only through direct Windmill endpoints but also via Nextcloud proxy paths.

During the same period, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its list of known exploited vulnerabilities. Other significant vulnerabilities include unauthenticated remote code execution flaws in WordPress and Langflow. CISA has mandated that federal agencies remediate these vulnerabilities by July 24, 2026.