Cybersecurity researchers have uncovered critical vulnerabilities in the Windmill developer platform and its integration within Nextcloud Flow, exposing organizations to severe remote code execution (RCE) risks.
These flaws allow unauthenticated attackers to gain complete control of affected systems without requiring any login credentials, making them highly dangerous in real-world environments.
The most critical issue, tracked as CVE-2026-29059, carries a maximum CVSS score of 10.0. It is a path traversal vulnerability caused by improper validation of file paths in the get_log_file endpoint.
This flaw allows attackers to access sensitive files by exploiting directory traversal sequences.
As a result, threat actors can retrieve application secrets, configuration files, and stored credentials, which can then be used to execute arbitrary code on the system.
In containerized deployments such as Docker, the impact becomes even more severe. Attackers can potentially escape the container environment and compromise the underlying host machine, expanding the scope of the attack beyond the application itself.
A second critical vulnerability, currently awaiting a CVE identifier, is an authenticated SQL injection flaw with a CVSS score of 9.4.
This issue affects Windmill instances where attackers already have low-level operator access. By exploiting this flaw, attackers can manipulate backend database queries, extract sensitive data from PostgreSQL databases, and escalate privileges to gain “super admin” access.
This effectively grants full control over the platform.
The risk is further amplified in environments using Nextcloud Flow, which integrates the Windmill automation engine.
Researchers identified a major misconfiguration that exposes an internal network endpoint to the public internet.
This allows attackers to bypass Nextcloud’s security controls entirely. Using advanced techniques such as triple URL encoding, attackers can evade filtering mechanisms, access environment variables, and extract sensitive secrets.
These secrets can then be used to create unauthorized administrator accounts and take over the entire Nextcloud instance.
The situation has become more critical following the release of a proof-of-concept exploit framework named “Windfall,” developed by security researcher Chocapikk.
This advanced tool automates the exploitation process by detecting the target environment and selecting the most effective attack method.
It significantly lowers the barrier for attackers, enabling even less skilled threat actors to launch sophisticated attacks.
One of the most concerning features of Windfall is its “Ghost Mode.” This capability removes evidence of compromise by deleting logs, job histories, and execution traces from the backend database.
As a result, incident response teams may struggle to detect or investigate breaches, increasing the likelihood of prolonged, undetected attacks.
The exploit framework also references multiple related vulnerabilities, including CVE-2026-23695, CVE-2026-23696, CVE-2026-23697, and CVE-2026-23698, indicating a broader attack surface across the platform.
To mitigate these risks, administrators are strongly advised to upgrade immediately to Windmill version 1.603.3 and Nextcloud Flow version 1.3.0.
Additional security measures include enforcing strict input validation, implementing proper authentication controls, running containers as non-root users, and restricting Docker socket access.
If patching is not immediately possible, disabling the Nextcloud Flow app can help reduce exposure.
Given the availability of a public exploit and the critical nature of these vulnerabilities, organizations must act quickly to prevent potential data breaches, system compromise, and widespread network intrusion.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google