Windmill

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    4
    High Level Threats
    0
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-47107

    Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration

    Last Modified: Jul 14, 2026
    Published: May 19, 2026

    CVE-2026-23696

    Windmill < 1.603.3 File Ownership Handling SQLi RCE

    Last Modified: Jul 14, 2026
    Published: Apr 07, 2026

    CVE-2026-22683

    Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE

    Last Modified: Apr 24, 2026
    Published: Apr 07, 2026

    CVE-2026-33881

    Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable interpolation in NativeTS executor

    Last Modified: Apr 08, 2026
    Published: Mar 27, 2026

    CVE-2026-29059

    Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly

    Last Modified: Apr 15, 2026
    Published: Mar 06, 2026
    Items Per Page
    Windmill Vulnerabilities & Security CVEs | CVE-DB