Windmill < 1.603.3 - Operator Authorization Bypass
CVE-2026-22683
Verified
Description
Windmill versions 1.276.0 through 1.603.2 contain an authorization bypass vulnerability in the folder management API endpoints. The endpoints for creating, deleting, and managing folder ownership do not enforce role-based access control for operator-level users. In Windmill, operators are restricted users intended to only execute existing scripts, but due to missing server-side authorization checks, operators can create folders, manage folder permissions, and access owner management endpoints. This bypass serves as the prerequisite for exploiting CVE-2026-23696 (SQL injection via folder addowner) enabling full privilege escalation from operator to super admin with remote code execution.
Severity
High
CVSS Score
8.1
Exploit Probability
3%
Affected Product
windmill
Published Date
July 21, 2026
Template Author
chocapikk, dhiyaneshdk
CVE-2026-22683.yaml
8.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-22683
CWE ID:
cwe-862
Remediation Steps
Update Windmill to version 1.603.3 or later which properly enforces operator role restrictions on folder management and job execution endpoints.