Authorization Bypass in Vito Web Application by Vito Deploy
CVE-2026-29789
10CRITICAL
What is CVE-2026-29789?
Vito is a self-hosted web application for managing servers and deploying PHP applications. A missing authorization check in the workflow site-creation actions allows authenticated attackers with write access in one project to manipulate sites on servers belonging to other projects by specifying a foreign server_id. This issue impacts versions prior to 3.20.3 and has been resolved in the latest release.
Affected Version(s)
vito < 3.20.3
