Back to overview

CVE-2026-29789

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation actions allows an authenticated attacker with workflow write access in one project to create/manage sites on servers belonging to other projects by supplying a foreign server_id. This issue has been patched in version 3.20.3.

Metadata

CVE ID
CVE-2026-29789
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-03-04 16:26 UTC
Published
2026-03-06 20:35 UTC
Last updated
2026-03-09 20:54 UTC
Primary CWE
CWE-862
CWE-862: Missing Authorization
Vendor / Product
vitodeploy / vito
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
vitodeploy vito < 3.20.3
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862: Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (4)
Back to overview