📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2026-22683

High
CWE-862 — Weakness Type
Published: Apr 7, 2026  ·  Modified: Apr 14, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not enforce the Operator restriction on workspace endpoints, allowing an Operator to create and update scripts, flows, apps, and raw_apps. Since Operators can also execute scripts via the jobs API, this allows direct privilege escalation to remote code execution within the Windmill deployment. This vulnerability has existed since the introduction of the Operator role in version 1.56.0.

🤖 AI Executive Summary

Windmill versions 1.56.0-1.614.0 contain a critical authorization bypass allowing Operator-role users to create and modify entities (scripts, flows, apps) they should not have access to, leading to privilege escalation and remote code execution. This vulnerability has persisted since the Operator role's introduction and affects all deployments using these versions. No patch is currently available, requiring immediate compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 22, 2026 16:39
🇸🇦 Saudi Arabia Impact Assessment
High impact for Saudi organizations using Windmill for workflow automation, particularly in: (1) Banking sector (SAMA-regulated institutions) - risk of unauthorized script execution in payment processing systems; (2) Government agencies (NCA oversight) - potential compromise of administrative workflows and data access; (3) Energy sector (ARAMCO, utilities) - critical infrastructure automation at risk; (4) Telecom operators (STC, Mobily) - network automation and provisioning systems vulnerable; (5) Healthcare providers - patient data processing workflows compromised. The privilege escalation to RCE is particularly severe in air-gapped or sensitive environments.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Energy and Utilities Telecommunications Healthcare Manufacturing Retail and E-commerce
⚖️ Saudi Risk Score (AI)
8.9
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all Windmill deployments to identify versions 1.56.0-1.614.0
2. Review audit logs for Operator role API calls to workspace endpoints (script creation, flow creation, app creation, raw_app endpoints)
3. Identify and disable all Operator accounts not requiring active use
4. Implement network segmentation to restrict Windmill API access

COMPENSATING CONTROLS (until patch available):
1. Deploy API gateway/WAF rules to block Operator role requests to: /api/w/*/scripts, /api/w/*/flows, /api/w/*/apps, /api/w/*/raw_apps endpoints
2. Implement role-based API access controls at reverse proxy level
3. Enable comprehensive API logging and alerting for all workspace entity creation/modification attempts
4. Restrict job execution API access to authenticated Admin roles only
5. Monitor for suspicious script/flow creation patterns

DETECTION RULES:
- Alert on Operator role API calls to workspace entity creation endpoints
- Monitor for script execution by Operator-created entities
- Track privilege escalation attempts via jobs API
- Flag rapid entity creation/modification by Operator accounts

PATCHING:
- Await vendor patch release; do not upgrade to unverified versions
- When patch available, test in isolated environment before production deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع نشرات Windmill لتحديد الإصدارات 1.56.0-1.614.0
2. مراجعة سجلات التدقيق لاستدعاءات API لدور المشغل إلى نقاط نهاية مساحة العمل
3. تحديد وتعطيل جميع حسابات المشغل التي لا تتطلب استخدام نشط
4. تنفيذ تقسيم الشبكة لتقييد وصول API في Windmill

الضوابط التعويضية (حتى توفر التصحيح):
1. نشر قواعد بوابة API/WAF لحظر طلبات دور المشغل إلى نقاط النهاية
2. تنفيذ ضوابط وصول API قائمة على الأدوار على مستوى الوكيل العكسي
3. تفعيل تسجيل التنبيهات الشاملة لجميع محاولات إنشاء/تعديل كيانات مساحة العمل
4. تقييد وصول API تنفيذ الوظائف إلى أدوار المسؤول المصرح بها فقط
5. مراقبة أنماط إنشاء/تعديل البرامج النصية المريبة

قواعد الكشف:
- تنبيه على استدعاءات API لدور المشغل إلى نقاط نهاية إنشاء كيانات مساحة العمل
- مراقبة تنفيذ البرامج النصية بواسطة الكيانات التي أنشأها المشغل
- تتبع محاولات تصعيد الامتيازات عبر API الوظائف
- وضع علامة على الإنشاء/التعديل السريع للكيانات بواسطة حسابات المشغل

التصحيح:
- انتظر إصدار تصحيح البائع؛ لا تقم بالترقية إلى إصدارات غير تم التحقق منها
- عند توفر التصحيح، اختبر في بيئة معزولة قبل نشر الإنتاج
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.9.1.1 - Access control policy and procedures ECC 2024 A.9.2.1 - User registration and access rights management ECC 2024 A.9.4.3 - Review of user access rights ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.4.1 - Event logging and monitoring
🔵 SAMA CSF
SAMA CSF ID.AC-1 - Access Control Policy SAMA CSF PR.AC-1 - Processes and procedures for access management SAMA CSF PR.AC-4 - Access rights and privileges management SAMA CSF DE.AE-1 - Audit and accountability mechanisms SAMA CSF RS.MI-2 - Incident response and recovery
🟡 ISO 27001:2022
ISO 27001:2022 A.5.3 - Segregation of duties ISO 27001:2022 A.8.2 - User access management ISO 27001:2022 A.8.3 - User responsibilities ISO 27001:2022 A.9.2 - User access provisioning ISO 27001:2022 A.9.4 - Access rights review ISO 27001:2022 A.12.4 - Logging and monitoring
🟣 PCI DSS v4.0.1
PCI DSS 7.1 - Limit access to system components by business need-to-know PCI DSS 7.2 - Establish an access control system PCI DSS 8.2 - Ensure proper user identification and authentication PCI DSS 10.2 - Implement automated audit trails
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-862
EPSS0.25%
Exploit No
Patch ✗ No
Published 2026-04-07
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.9
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-862
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.