CVE-2026-47107 Details
Description
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt from within script execution sandboxes. Attackers can exploit persistent poisoned entries across all subsequent script executions on the same worker pod to redirect hostnames, intercept DNS queries, perform transparent HTTPS man-in-the-middle attacks, and intercept WM_TOKEN JWTs to gain workspace-admin access to other users' workspaces.
A vulnerability exists in Windmill versions prior to 1.703.2, where nsjail sandbox configuration files incorrectly allow default permissions. The /etc directory is bind-mounted without proper read-write restrictions, enabling authenticated users to write arbitrary entries to critical system files such as /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt, all from within script execution sandboxes. This flaw can be exploited to create persistent, malicious entries that affect all subsequent script executions on the same worker pod. Such exploitation can redirect hostnames, intercept DNS queries, conduct transparent HTTPS man-in-the-middle attacks, and capture WM_TOKEN JWTs, granting workspace-admin access to victim workspaces across tenants.
Users can update to Windmill version 1.703.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/windmill-labs/windmill/pull/9194 | CISA-ADP | Issue TrackingVendor |
| https://github.com/windmill-labs/windmill/commit/f8467f38c8a053117ce62f96684cfb15ef792f08 | [email protected] | Source CodeVendor |
| https://github.com/windmill-labs/windmill/pull/9194 | [email protected] | Issue TrackingVendor |
| https://github.com/windmill-labs/windmill/releases/tag/v1.703.2 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/windmill-incorrect-default-permissions-in-nsjail-configuration | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Windmill | < 1.703.2 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |
Volerion