CVE-2026-23696: Windmill < 1.603.3 File Ownership Handling SQLi RCE
Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
windmillto a version that resolves this vulnerability.Fixed in 1.603.3 - Upgrade
Upgrade
windmillto a version that resolves this vulnerability.Fixed in 1.276.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23696?
CVE-2026-23696 has a high severity given its potential for remote code execution through SQL injection.
How do I fix CVE-2026-23696?
To mitigate CVE-2026-23696, upgrade Windmill CE and EE to version 1.603.3 or later.
Who is affected by CVE-2026-23696?
CVE-2026-23696 affects users of Windmill CE and EE versions between 1.276.0 and 1.603.2.
What type of vulnerability is CVE-2026-23696?
CVE-2026-23696 is classified as an SQL injection vulnerability that can lead to remote code execution.
Can CVE-2026-23696 be exploited by unauthenticated users?
No, CVE-2026-23696 requires authentication to exploit the file ownership handling functionality.