No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/windmill-labs/windmill |
|
Tue, 11 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Windmill-labs
Windmill-labs windmill |
|
| Vendors & Products |
Windmill-labs
Windmill-labs windmill |
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned to any workspace member who queries the drafts endpoint. Sensitive credentials stored in these drafts are exposed across ACL boundaries. | |
| Title | Windmill Labs Windmill - Information Disclosure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:37:03.236Z
Reserved: 2026-08-10T10:32:49.080Z
Link: CVE-2026-72539
Updated: 2026-08-11T12:36:12.866Z
Status : Received
Published: 2026-08-11T12:17:39.220
Modified: 2026-08-11T13:19:02.590
Link: CVE-2026-72539
No data.
OpenCVE Enrichment
Updated: 2026-08-11T18:15:07Z