CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-23696

Critical · CVSS 9.9

Windmill CE/EE — SQL Injection leading to RCE (JWT secret exfiltration via owner parameter)

CVSS
9.9
nvd
EPSS
5.06%
91th pct
KEV
No
Class
oss containerizable
CWE-89

Description

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.

Search profile — drives PoC discovery

Symbols ownerfolder ownership managementJWT signing secretworkflow execution endpoints942fb629210ebb287f48467d1535ffde3a3eeafe
Keywords CVE-2026-23696Windmill SQL injectionWindmill owner parameter SQLiWindfall Windmill RCEWindmill JWT secret injectionChocapikk WindfallWindmill folder ownership sqliwindmill-labs sqli rceWindmill 1.276.0 1.603.2 vulnerability
Versions: 1.276.0 through 1.603.2

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z