Impact
A missing authorization check in the update_resource_type endpoint of Windmill Labs Windmill allows any authenticated workspace member to overwrite any resource type schema, bypassing the administrator permission enforcement that protects the corresponding delete_resource_type action. By modifying these schemas, an attacker can corrupt the definitions that workflows rely on, potentially rendering them non‑functional or altering their behavior. This constitutes an authorization bypass that can lead to compromise of workflow integrity and availability.
Affected Systems
Windmill Labs Windmill through version 1.783.0 is affected. No other versions or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated workspace member user; exploitation requires no additional privileges beyond normal workspace membership.
OpenCVE Enrichment