CVE-2026-29059: Unauthenticated Path Traversal in Windmill and Nextcloud Flow
Introduction Modern enterprise automation relies heavily on unified workflow engines to connect disparate infrastructure components, manage background tasks, and streamline internal processes. Platforms such as Windmill and its integrations—including Nextcloud Flow—provide robust execution environments for scripts and automated jobs. However, because these systems process sensitive data and hold elevated permissions across networks, any inherent flaw severely expands an organization’s attack surface. When central infrastructure automation