Impact
The vulnerability is a missing authorization check that allows users with the Operator role to create and modify entities such as scripts, flows, apps, and raw_app objects through the backend API. Operators are documented and priced as unable to perform those actions, yet the API enforces the restriction only on selected endpoints, leaving operators able to add or update scripts. Because operators can execute scripts via the jobs API, the flaw permits an attacker to gain full code execution on the Windmill deployment. This results in complete compromise of confidentiality, integrity, and availability of the system.
Affected Systems
Windmill releases from version 1.56.0 up to, but not including, 1.615.0 are affected. This includes the Windmill Community Edition (CE) and Enterprise Edition (EE) from Windmill Labs, as well as the Flow component of Nextcloud. The issue is resolved in release 1.615.0 and later versions. All deployments running a version in the vulnerable range should be upgraded or otherwise mitigated.
Risk and Exploitability
The flaw rates a CVSS score of 8.7, indicating a high severity vulnerability. With an EPSS score of 3%, the likelihood of exploitation is considered moderate based on industry metrics. Attackers require only authenticated access as a user with the Operator role, which may be granted to non‑privileged users. Based on the description, the likely attack vector is network‑based, using crafted HTTP API requests to the Windmill backend. This leads to remote code execution. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS and direct RCE potential warrant immediate remediation.
OpenCVE Enrichment