CrowdSecLive Exploit Tracker
Background NoiseCVE-2026-29059Public Exploit

Windmill - Path Traversal (CVE-2026-29059)

PublishedMar 6, 2026
First SeenJul 2, 2026
Last Seen
Reported
CVSS6.9
web_applicationenterprise_software

Description

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences. This issue has been patched in version 1.603.3.

psychologyCrowdSec Analysis

CVE-2026-29059 is a path traversal vulnerability in Windmill, an open-source developer platform, affecting versions prior to 1.603.3. This flaw allows unauthenticated attackers to exploit the get_log_file endpoint by manipulating the filename parameter, enabling unauthorized reading of arbitrary files on the server. Attackers could leverage this vulnerability to access sensitive information and potentially aid in further attacks against the system. The issue has been addressed in version 1.603.3.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

CrowdSec network data shows that most actors exploiting CVE-2026-29059 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2026-29059 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2026-29059 is currently experiencing high visibility and active exploitation across the internet.

Attackers exploit the /api/w/_/jobs_u/get_log_file/ and related endpoints by supplying path traversal sequences (e.g., ..%2F..%2F..%2Fetc%2Fpasswd) in the URL to read arbitrary files from the server without authentication.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-03-06
Rule Released2026-07-01
CrowdSec First Seen2026-07-02

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.