PT-2026-70117 · Windmill · Windmill
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Windmill Labs Windmill versions prior to 1.783.1
Description
A missing authorization issue allows authenticated operators to write job progress and read job metrics for any job within a workspace, regardless of ownership. This occurs because the
job metrics handlers do not utilize an authorization extractor, which bypasses workspace-level access controls. Consequently, an operator can monitor sensitive job execution data and inject misleading progress for jobs they do not own.Recommendations
Update Windmill Labs Windmill to version 1.783.1 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windmill