CVE-2026-47107 – windmill

CVSS 8.1 IMPORTANT

“Permission mistakes in automation platforms can quietly give attackers more access than they should ever have.”

windmill-labs released a patch for a high-severity vulnerability affecting windmill. CVE-2026-47107 has a CVSS score of 8.1, which is High severity.

The vulnerability involves incorrect permission assignment that could allow privilege escalation in affected windmill environments. Public proof-of-concept code is available. The update strengthens permission management controls and reduces the risk of unauthorized access to automation workflows, jobs, and administrative functions.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-276
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.