CVE-2026-26964 describes an information disclosure vulnerability in Windmill versions 1.634.6 and below, where non-admin users can access Slack OAuth client secrets. This flaw stems from a legacy issue where the secret was not properly redacted from workspace settings, allowing any authenticated workspace member to retrieve it via the GET /api/w/{workspace}/workspaces/get_settings endpoint. The vulnerability has a low severity CVSS score of 2.7, indicating a low impact (C:L) and requiring high privileges (PR:H) for exploitation. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.635.0CPE matchmatch criteria | cpe:2.3:a:windmill:windmill:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.