/Vulnerability Library

Windmill < 1.603.3 - Operator Authorization Bypass

CVE-2026-22683
Verified

Description

Windmill versions 1.276.0 through 1.603.2 contain an authorization bypass vulnerability in the folder management API endpoints. The endpoints for creating, deleting, and managing folder ownership do not enforce role-based access control for operator-level users. In Windmill, operators are restricted users intended to only execute existing scripts, but due to missing server-side authorization checks, operators can create folders, manage folder permissions, and access owner management endpoints. This bypass serves as the prerequisite for exploiting CVE-2026-23696 (SQL injection via folder addowner) enabling full privilege escalation from operator to super admin with remote code execution.

Severity

High

CVSS Score

8.1

Exploit Probability

3%

Affected Product

windmill

Published Date

July 21, 2026

Template Author

chocapikk, dhiyaneshdk

CVE-2026-22683.yaml
8.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-22683
CWE ID:
cwe-862

References

https://github.com/Chocapikk/Windfallhttps://github.com/windmill-labs/windmill/commit/942fb629210ebb287f48467d1535ffde3a3eeafehttps://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/https://nvd.nist.gov/vuln/detail/CVE-2026-22683

Remediation Steps

Update Windmill to version 1.603.3 or later which properly enforces operator role restrictions on folder management and job execution endpoints.