CVE-2026-72539: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Windmill Labs Windmill
CVE-2026-72539 is an information disclosure vulnerability in Windmill Labs Windmill up to version 1.783.0. It allows any authenticated workspace member to access legacy ownerless draft scripts containing plaintext resource credentials. These drafts have a null owner email, which causes them to bypass access control enforcement and be returned to any querying workspace member. This results in exposure of sensitive credentials across access control boundaries.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-72539 affects Windmill Labs Windmill through version 1.783.0. It involves an information disclosure flaw where legacy draft scripts without an assigned owner email bypass access control lists (ACLs). Any authenticated member of a workspace can query the drafts endpoint and receive these ownerless drafts, which contain plaintext resource credentials. This exposure allows unauthorized actors within the workspace to access sensitive information that should be restricted.
Potential Impact
The impact of this vulnerability is the unauthorized disclosure of sensitive plaintext resource credentials to any authenticated workspace member. This could lead to credential compromise and potential misuse of resources that rely on these credentials. The CVSS 3.1 base score is 6.5 (medium severity), reflecting a network attack vector with low attack complexity, requiring privileges but no user interaction, and resulting in high confidentiality impact without integrity or availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation has been documented at this time. Until a patch is available, restrict workspace membership to trusted users only and monitor for any unusual access patterns related to draft scripts. Follow vendor updates closely for any forthcoming patches or official mitigation instructions.
CVE-2026-72539: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Windmill Labs Windmill
Description
CVE-2026-72539 is an information disclosure vulnerability in Windmill Labs Windmill up to version 1.783.0. It allows any authenticated workspace member to access legacy ownerless draft scripts containing plaintext resource credentials. These drafts have a null owner email, which causes them to bypass access control enforcement and be returned to any querying workspace member. This results in exposure of sensitive credentials across access control boundaries.
CVSS v3.1
Score 6.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-72539 affects Windmill Labs Windmill through version 1.783.0. It involves an information disclosure flaw where legacy draft scripts without an assigned owner email bypass access control lists (ACLs). Any authenticated member of a workspace can query the drafts endpoint and receive these ownerless drafts, which contain plaintext resource credentials. This exposure allows unauthorized actors within the workspace to access sensitive information that should be restricted.
Potential Impact
The impact of this vulnerability is the unauthorized disclosure of sensitive plaintext resource credentials to any authenticated workspace member. This could lead to credential compromise and potential misuse of resources that rely on these credentials. The CVSS 3.1 base score is 6.5 (medium severity), reflecting a network attack vector with low attack complexity, requiring privileges but no user interaction, and resulting in high confidentiality impact without integrity or availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation has been documented at this time. Until a patch is available, restrict workspace membership to trusted users only and monitor for any unusual access patterns related to draft scripts. Follow vendor updates closely for any forthcoming patches or official mitigation instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-10T10:32:49.080Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7b0702bf8831d539a0cbf1
Added to database: 08/11/2026, 11:26:58 UTC
Last enriched: 08/11/2026, 11:43:57 UTC
Last updated: 08/11/2026, 12:01:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.