Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/windmill-labs/windmill |
|
Tue, 11 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Windmill-labs
Windmill-labs windmill |
|
| Vendors & Products |
Windmill-labs
Windmill-labs windmill |
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in the workspace regardless of ownership. The job_metrics handlers accept no authorization extractor, bypassing workspace-level access controls. An operator can monitor sensitive job execution data and inject misleading progress for jobs they do not own. | |
| Title | Windmill Labs Windmill - Missing Authorization | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:33:47.646Z
Reserved: 2026-08-10T10:32:49.080Z
Link: CVE-2026-72542
Updated: 2026-08-11T12:26:18.755Z
Status : Received
Published: 2026-08-11T12:17:39.607
Modified: 2026-08-11T13:19:02.923
Link: CVE-2026-72542
No data.
OpenCVE Enrichment
Updated: 2026-08-11T18:00:22Z