PULSE
EN VIVO16señales / 24h
FEED
ransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcareransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcare
← Todos los CVEs
CVE Watch11 ago 2026

CVE-2026-72541

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any r

CVSS

6.5

Medio

EPSS

KEV

Exploit Today

0-100

Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-306

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource type schema via the update_resource_type endpoint. The endpoint omits the administrator permission check that the corresponding delete_resource_type endpoint enforces. An attacker with workspace member privileges can corrupt resource type definitions, breaking workflows that depend on them.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-649218.8 ALT
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.6h
CVE-2026-627777.8 ALT
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613677.8 ALT
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613657.8 ALT
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613647.8 ALT
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613567.8 ALT
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h