Windfall - Unauthenticated RCE exploit chain for Windmill & Nextcloud Flow (CVE-2026-29059). Path traversal + credential leak + PostgreSQL heap dump + Nextcloud AppAPI takeover.
python security exploit nextcloud rce sql-injection pentesting cve windmill security-research path-traversal cve-2026-23696 cve-2026-29059 cve-2026-22683
-
Updated
Apr 7, 2026 - Ruby