📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global ransomware Multiple Sectors / Enterprise CRITICAL 1h Global general Technology and Legal MEDIUM 1h Global ransomware Financial Services / Cryptocurrency CRITICAL 2h Global general Industrial Control Systems / Operational Technology HIGH 3h Global apt Managed Service Providers (MSPs) / IT Services HIGH 4h Global vulnerability Enterprise Software HIGH 4h Global general Cybersecurity Operations HIGH 4h Global general Cybersecurity Industry LOW 4h Global supply_chain Multiple Sectors CRITICAL 4h Global vulnerability Government/Federal Agencies HIGH 5h Global ransomware Multiple Sectors / Enterprise CRITICAL 1h Global general Technology and Legal MEDIUM 1h Global ransomware Financial Services / Cryptocurrency CRITICAL 2h Global general Industrial Control Systems / Operational Technology HIGH 3h Global apt Managed Service Providers (MSPs) / IT Services HIGH 4h Global vulnerability Enterprise Software HIGH 4h Global general Cybersecurity Operations HIGH 4h Global general Cybersecurity Industry LOW 4h Global supply_chain Multiple Sectors CRITICAL 4h Global vulnerability Government/Federal Agencies HIGH 5h Global ransomware Multiple Sectors / Enterprise CRITICAL 1h Global general Technology and Legal MEDIUM 1h Global ransomware Financial Services / Cryptocurrency CRITICAL 2h Global general Industrial Control Systems / Operational Technology HIGH 3h Global apt Managed Service Providers (MSPs) / IT Services HIGH 4h Global vulnerability Enterprise Software HIGH 4h Global general Cybersecurity Operations HIGH 4h Global general Cybersecurity Industry LOW 4h Global supply_chain Multiple Sectors CRITICAL 4h Global vulnerability Government/Federal Agencies HIGH 5h
Vulnerabilities

CVE-2026-47107

High
CWE-276 — Weakness Type
Published: May 19, 2026  ·  Modified: May 26, 2026  ·  Source: NVD
CVSS v3
8.1
🔗 NVD Official
📄 Description (English)

Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt from within script execution sandboxes. Attackers can exploit persistent poisoned entries across all subsequent script executions on the same worker pod to redirect hostnames, intercept DNS queries, perform transparent HTTPS man-in-the-middle attacks, and intercept WM_TOKEN JWTs to gain workspace-admin access to other users' workspaces.

🤖 AI Executive Summary

Windmill versions prior to 1.703.2 contain a critical sandbox escape vulnerability allowing authenticated users to modify system configuration files (/etc/hosts, /etc/resolv.conf, /etc/ssl/certs) within script execution environments. This enables DNS poisoning, HTTPS man-in-the-middle attacks, and token interception to compromise workspace security. The vulnerability affects all subsequent script executions on compromised worker pods, creating persistent attack vectors.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 21, 2026 17:07
🇸🇦 Saudi Arabia Impact Assessment
High impact for Saudi organizations using Windmill for workflow automation, particularly in: (1) Banking sector (SAMA-regulated institutions) - risk of JWT token interception and unauthorized workspace access to financial systems; (2) Government agencies (NCA oversight) - potential compromise of administrative automation workflows; (3) Telecom operators (STC, Mobily) - DNS poisoning could redirect critical infrastructure communications; (4) Energy sector (ARAMCO, SEC) - HTTPS MITM attacks on operational technology integrations; (5) Healthcare providers - patient data exposure through compromised automation scripts. The persistent nature of the vulnerability across worker pods creates sustained compromise risk.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Energy and Utilities Healthcare Manufacturing Retail and E-commerce
⚖️ Saudi Risk Score (AI)
8.7
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all Windmill deployments to identify version < 1.703.2
2. Restrict network access to Windmill worker pods to trusted networks only
3. Implement pod security policies to prevent /etc bind-mount modifications
4. Review audit logs for suspicious /etc file modifications within script execution contexts
5. Rotate all WM_TOKEN JWTs and workspace admin credentials immediately

COMPENSATING CONTROLS (until patch available):
1. Deploy read-only filesystem enforcement at container runtime level using seccomp/AppArmor profiles
2. Implement network policies to restrict egress from worker pods to DNS/HTTPS services
3. Use immutable container images with verified /etc/hosts, /etc/resolv.conf, /etc/ssl/certs checksums
4. Enable audit logging for all file access within /etc directories
5. Implement certificate pinning for critical HTTPS connections
6. Deploy network-based DNS query monitoring to detect poisoning attempts

DETECTION RULES:
1. Monitor for write operations to /etc/hosts, /etc/resolv.conf, /etc/ssl/certs from within container namespaces
2. Alert on DNS query anomalies or resolution changes for critical hostnames
3. Detect TLS certificate validation failures or unexpected CA certificate additions
4. Monitor for WM_TOKEN usage from unexpected source IPs or workspaces
5. Track failed authentication attempts following token interception patterns
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع نشرات Windmill لتحديد الإصدار < 1.703.2
2. تقييد الوصول إلى شبكة حاويات عمل Windmill للشبكات الموثوقة فقط
3. تنفيذ سياسات أمان الحاويات لمنع تعديلات ربط /etc
4. مراجعة سجلات التدقيق للتعديلات المريبة على ملفات /etc داخل سياقات تنفيذ البرامج النصية
5. تدوير جميع رموز WM_TOKEN وبيانات اعتماد مسؤول مساحة العمل فوراً

الضوابط التعويضية (حتى توفر التصحيح):
1. نشر فرض نظام الملفات للقراءة فقط على مستوى وقت تشغيل الحاوية باستخدام ملفات تعريف seccomp/AppArmor
2. تنفيذ سياسات الشبكة لتقييد الخروج من حاويات العمل إلى خدمات DNS/HTTPS
3. استخدام صور حاويات ثابتة مع مجاميع تحقق من /etc/hosts و /etc/resolv.conf و /etc/ssl/certs
4. تفعيل تسجيل التدقيق لجميع عمليات الوصول إلى الملفات داخل دلائل /etc
5. تنفيذ تثبيت الشهادات للاتصالات HTTPS الحرجة
6. نشر مراقبة استعلامات DNS على مستوى الشبكة للكشف عن محاولات التسميم

قواعد الكشف:
1. مراقبة عمليات الكتابة إلى /etc/hosts و /etc/resolv.conf و /etc/ssl/certs من داخل مساحات أسماء الحاويات
2. التنبيه على شذوذ استعلامات DNS أو تغييرات الدقة للأسماء المضيفة الحرجة
3. الكشف عن فشل التحقق من شهادة TLS أو إضافات شهادات CA غير المتوقعة
4. مراقبة استخدام WM_TOKEN من عناوين IP أو مساحات عمل غير متوقعة
5. تتبع محاولات المصادقة الفاشلة بعد أنماط اعتراض الرموز
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies (unauthorized workspace access) ECC 2024 A.5.2.1 - User Registration and Access Management (JWT token compromise) ECC 2024 A.6.1.2 - Cryptography (HTTPS MITM attacks) ECC 2024 A.8.1.1 - Audit Logging (detection of /etc modifications) ECC 2024 A.12.4.1 - Event Logging (security event monitoring)
🔵 SAMA CSF
SAMA CSF ID.AM-1 - Asset Management (Windmill deployment inventory) SAMA CSF PR.AC-1 - Access Control (workspace authentication compromise) SAMA CSF PR.DS-2 - Data Security (DNS poisoning, HTTPS MITM) SAMA CSF DE.AE-1 - Anomalies and Events (suspicious /etc modifications) SAMA CSF RS.AN-1 - Analysis (incident investigation of token interception)
🟡 ISO 27001:2022
ISO 27001:2022 A.5.3 - Segregation of Duties (workspace isolation failure) ISO 27001:2022 A.6.2 - User Access Management (authentication bypass via token interception) ISO 27001:2022 A.8.3 - Cryptography (HTTPS MITM attacks) ISO 27001:2022 A.8.15 - Logging (audit trail of /etc modifications) ISO 27001:2022 A.12.4.1 - Event Logging and Monitoring
🟣 PCI DSS v4.0.1
PCI DSS 1.1 - Firewall Configuration Standards (network segmentation of worker pods) PCI DSS 2.1 - Default Security Parameters (sandbox configuration hardening) PCI DSS 6.2 - Security Patches (Windmill version management) PCI DSS 10.2 - User Access Logging (WM_TOKEN usage monitoring)
📊 CVSS Score
8.1
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score8.1
CWECWE-276
EPSS0.02%
Exploit No
Patch ✗ No
Published 2026-05-19
Source Feed nvd
🇸🇦 Saudi Risk Score
8.7
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-276
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.