CVE-2026-47107 – windmill
CVSS 8.1
IMPORTANT
“Permission mistakes in automation platforms can quietly give attackers more access than they should ever have.”
windmill-labs released a patch for a high-severity vulnerability affecting windmill. CVE-2026-47107 has a CVSS score of 8.1, which is High severity.
The vulnerability involves incorrect permission assignment that could allow privilege escalation in affected windmill environments. Public proof-of-concept code is available. The update strengthens permission management controls and reduces the risk of unauthorized access to automation workflows, jobs, and administrative functions.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-276
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.