No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/windmill-labs/windmill |
|
Tue, 11 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Windmill-labs
Windmill-labs windmill |
|
| Vendors & Products |
Windmill-labs
Windmill-labs windmill |
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in the workspace regardless of ownership. The job_metrics handlers accept no authorization extractor, bypassing workspace-level access controls. An operator can monitor sensitive job execution data and inject misleading progress for jobs they do not own. | |
| Title | Windmill Labs Windmill - Missing Authorization | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:33:47.646Z
Reserved: 2026-08-10T10:32:49.080Z
Link: CVE-2026-72542
Updated: 2026-08-11T12:26:18.755Z
Status : Received
Published: 2026-08-11T12:17:39.607
Modified: 2026-08-11T13:19:02.923
Link: CVE-2026-72542
No data.
OpenCVE Enrichment
Updated: 2026-08-11T18:00:22Z