CVE-2026-23696
Windmill < 1.603.3 File Ownership Handling SQLi RCE
Description
Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Windmill Labs | Windmill CE (Community Edition) | 1.276.0 to 1.603.2 1.603.3 (unaffected) |
| Windmill Labs | Windmill EE (Enterprise Edition) | 1.276.0 to 1.603.2 1.603.3 (unaffected) |
References
7 LinksRecord Details
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.