top of page
perceptive_background_267k.jpg

Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authoriz…

Published:

5 maart 2026 om 23:00:00

Alert date:

6 maart 2026 om 22:01:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Vito, a self-hosted web application for managing servers and deploying PHP applications, contains a missing authorization check vulnerability in workflow site-creation actions prior to version 3.20.3. The vulnerability allows authenticated attackers with workflow write access in one project to create and manage sites on servers belonging to other projects by supplying a foreign server_id. This represents a privilege escalation issue that could allow unauthorized cross-project access. The vulnerability has been patched in version 3.20.3.

Technical details

Mitigation steps:

Affected products:

Vito

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page