PT-2026-70116 · Windmill · Windmill
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Windmill Labs Windmill versions prior to 1.783.1
Description
A missing authorization issue allows authenticated workspace members to overwrite any resource type schema. This occurs because the 'update resource type' endpoint fails to perform the administrator permission check that is present in the 'delete resource type' endpoint. An attacker with workspace member privileges can exploit this to corrupt resource type definitions, which may break dependent workflows.
Recommendations
Update Windmill Labs Windmill to version 1.783.1 or later.
Restrict access to the 'update resource type' endpoint to authorized administrators only.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windmill