Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Windmill
Windmill windmill |
|
| CPEs | cpe:2.3:a:nextcloud:flow:*:*:*:*:*:*:*:* cpe:2.3:a:windmill:windmill:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Windmill
Windmill windmill |
Mon, 13 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud flow Windmill-labs Windmill-labs windmill |
|
| Vendors & Products |
Nextcloud
Nextcloud flow Windmill-labs Windmill-labs windmill |
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not enforce the Operator restriction on workspace endpoints, allowing an Operator to create and update scripts, flows, apps, and raw_apps. Since Operators can also execute scripts via the jobs API, this allows direct privilege escalation to remote code execution within the Windmill deployment. This vulnerability has existed since the introduction of the Operator role in version 1.56.0. | |
| Title | Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-13T13:04:17.928Z
Reserved: 2026-01-08T19:04:26.365Z
Link: CVE-2026-22683
Updated: 2026-04-13T13:00:41.979Z
Status : Analyzed
Published: 2026-04-07T17:16:27.037
Modified: 2026-04-24T16:49:50.443
Link: CVE-2026-22683
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:47:39Z