A severe security vulnerability in the open-source Windmill platform, identified as CVE-2026-29059, is being actively exploited by hackers to read arbitrary server files without authentication. This high-severity flaw, with a CVSS score of 7.5, allows attackers to traverse paths and access sensitive files by manipulating the "get_log_file" endpoint. The vulnerability stems from the insecure concatenation of the filename parameter, enabling hackers to bypass authentication mechanisms and access restricted files. As a result, Windmill users are exposed to potential data breaches and unauthorized access to sensitive information1. The active exploitation of this vulnerability expands the attack surface, making it essential for entities using Windmill to prioritize mitigation based on their exposure and evidence of exploitation. This vulnerability poses a significant risk to Windmill users, highlighting the need for prompt patching and security updates to prevent further exploitation.