CVE-2026-29789Disclosure(vitodeploy / vito)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch vitodeploy vito systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation actions allows an authenticated attacker with workflow write access in one project to create/manage sites on servers belonging to other projects by supplying a foreign server_id. This issue has been patched in version 3.20.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vito

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-06); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
vito

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 2Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 103-0603-07
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure1Patch1
2026-03-072
Disclosure2
Full discourse4 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29789 - Vito: Cross-project privilege escalation in workflow site-creation actions allows unauthorized server modification Intel Report: https://ift.tt/DyzqS7c

    Post summary

    This tweet announces CVE-2026-29789, describing a cross-project privilege escalation in workflow site‑creation actions that allows unauthorized server modification, but does not provide evidence of active exploitation, PoC, or patch information.

    1000044
    343 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29789 Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization … https://www.cve.org/CVERecord?id=CVE-2026-29789

    Post summary

    The post identifies CVE-2026-29789 as a missing‑authorization flaw in Vito before version 3.20.3, providing no exploit details, patch information, or evidence of active attacks.

    00000113
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29789 - Critical Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow sit... https://www.thehackerwire.com/vulnerability/CVE-2026-29789/ https://t.co/uke44g2DWR

    Post summary

    The tweet discloses a critical vulnerability (CVE-2026-29789) in Vito before version 3.20.3 caused by a missing authorization check in its workflow, linking to a source for more details. No PoC, exploit, patch, or active exploitation evidence is provided.

    0000043
    128 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29789: CRITICAL] Vulnerability in Vito web app (pre 3.20.3) allowed authenticated attackers to manage sites on servers of other projects. Patch available in version 3.20.3. #CyberSecurity#cve,CVE-2026-29789,#cybersecurity https://cvefind.com/CVE-2026-29789

    Post summary

    The post announces a critical vulnerability in the Vito web app and highlights the availability of a patch in version 3.20.3, providing a brief description of the exploitable behavior.

    0000048
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvitodeployvito---

Explore more