MEDIUMVulnerability

CVE-2026-72539

An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned to any workspace member who queries the drafts endpoint. Sensitive credentials stored in these drafts are exposed across ACL boundaries.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00305
cve_id
CVE-2026-72539
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-11T12:17:39.220
last_modified
2026-09-03T17:49:19.180
epss_percentile
0.22733

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72539 — Ninja Signal Threat Intelligence | Ninja Signal