← Back to browse · API

CVE-2026-29789

Severity
CRITICAL
CVSS
10.0
EPSS
0.00367
Risk score
40.13
CISA KEV
No
PoC
No
Published
2026-03-06
Modified
2026-03-09
First seen
2026-08-07
Aliases
EUVD-2026-10068
Products
vitodeploy:vito < 3.20.3
Sources
euvd EUVD-2026-10068

Description

Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation actions allows an authenticated attacker with workflow write access in one project to create/manage sites on servers belonging to other projects by supplying a foreign server_id. This issue has been patched in version 3.20.3.

References