logo

Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE

ID: e8451822-553b-5e53-87ab-55f551ea9a25

STIX ID: report--e8451822-553b-5e53-87ab-55f551ea9a25

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-05-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ProjectDiscovery disclosed three vulnerabilities in Versa Concerto — two critical flaws enabling authentication bypass and remote code execution (including an ld.so.preload RCE) and a high-severity Docker host write issue allowing full host compromise — provided PoCs and mitigation advice, and published details after a 90-day disclosure period; Versa later stated hotfixes and a GA release were made available and no exploitation was observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.