PULSE
LIVE23signals / 24h
FEED
ransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcareransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcare
← All CVEs
CVE WatchAug 11, 2026

CVE-2026-72542

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and rea

CVSS

5.4

Medium

EPSS

KEV

Exploit Today

0-100

Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-306

EPSS · 30d

Not enough EPSS history yet.

Technical description

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in the workspace regardless of ownership. The job_metrics handlers accept no authorization extractor, bypassing workspace-level access controls. An operator can monitor sensitive job execution data and inject misleading progress for jobs they do not own.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-649218.8 HIG
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.5h
CVE-2026-627777.8 HIG
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.5h
CVE-2026-613677.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5h
CVE-2026-613657.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5h
CVE-2026-613647.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5h
CVE-2026-613567.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.5h