CVE-2026-22683

Source
https://cve.org/CVERecord?id=CVE-2026-22683
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22683.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22683
Published
2026-04-07T16:50:30.297Z
Modified
2026-07-15T01:49:07.998590039Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE
Details

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not enforce the Operator restriction on workspace endpoints, allowing an Operator to create and update scripts, flows, apps, and raw_apps. Since Operators can also execute scripts via the jobs API, this allows direct privilege escalation to remote code execution within the Windmill deployment. This vulnerability has existed since the introduction of the Operator role in version 1.56.0.

Database specific
{
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22683.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/nextcloud/flow

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/flow
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.2.2"
        }
    ],
    "cpe": "cpe:2.3:a:nextcloud:flow:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}
Type
GIT
Repo
https://github.com/windmill-labs/windmill
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.56.0"
        },
        {
            "last_affected": "1.614.0"
        }
    ],
    "cpe": "cpe:2.3:a:windmill:windmill:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v1.0.1
v1.1.0
v1.2.0
v1.2.1
v1.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22683.json"