Snapshot 20962
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to navigationSkip to main content Revizto [email protected] Privacy PolicyOpens in new tab Revizto is the leading Integrated Collaboration Platform for the Architecture, Engineering, Construction & Operations (AECO) industry, transforming the way we design and build by driving efficiency, reducing errors, and simplifying complexity. From real-time coordination to automated clash detection and issue tracking, Revizto keeps all stakeholders aligned throughout the entire project lifecycle. Backed by Summit Partners, Revizto is relied on by firms around the world like Jacobs, AECOM, AtkinsRealis, McCarthy, Skanska, Stantec, and others to deliver projects with greater confidence and control. Compliance ISO 27001:2022 ISO 27017 SOC 2 Type2 CSA star level 1 UK Cyber Essentials U UK Secure by Design Resources View all Certificates ISO/IEC 27001:2022 Statement of ApplicabilityOpens in new tab Cyber Essentials certificate Opens in new tab Reports SOC2 Type2 report (2024) ISO/IEC 27001:2022, & 27017:2015 1st Surveillance Audit Report Pentest Report Workspace 2025 View 4 more Policy Access Control Policy Cryptography Policy View 17 more Other Shared responsibility matrixOpens in new tab Business Continuity and Disaster Recovery Plan Incident Response Plan Company StructureOpens in new tab Controls View all Infrastructure security Unique production database authentication enforced Encryption key access restricted Unique account authentication enforced View 16 more Infrastructure security controls Organizational security Asset disposal procedures utilized Production inventory maintained Portable media encrypted View 11 more Organizational security controls Product security Data encryption utilized Control self-assessments conducted Penetration testing performed View 1 more Product security control Internal security procedures Continuity and Disaster Recovery plans established Continuity and Disaster Recovery plans tested Configuration management system established View 30 more Internal security procedures controls Data and privacy Data retention procedures established Customer data deleted upon leaving Data classification policy established Data collected Customer personally identifiable information Employee personally identifiable information Customer project data Credit card information Personal health information Subprocessors View all AWS • Main Cloud hosting Switzerland, UK, Ireland, USA, Australia, Canada, Brazil, Singapore, Japan, United Arab Emirates Data Type: Full user data AliCloud • Separate Cloud hosting China, Kingdom of Saudi Arabia Data Type: Full user data Mailgun • Email delivery EU/US Data Type: Emails Amplitude • Analytics EU/US Data Type: Pseudonymized IDs FAQ View all Updates View all Security RVZ-SA-2026-002 - SAML Cross-Account Authentication Bypass in Revizto SSO Published May 14, 2026 Security Advisory — RVZ-SA-2026-002 SAML Cross-Account Authentication Bypass in Revizto SSO (SP-initiated flow) Field Value Revizto Vulnerability Advisory ID RVZ-SA-2026-002 Severity (CVSS 3.1 Base) 8.2 — High CVSS vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected product / component Revizto web platform — authentication service, SAML SP-initiated login flow Impacted versions All backend deployments prior to WEB-17260 (github.com/revizto/core PR #3038) Mitigated versions All production regions running post-WEB-17260 backend, deployed by [DD-Mon-2026 — to be filled by Infrastructure] Date published 13-May-2026 Last updated 13-May-2026 Summary During an internal security review, the Revizto Application Security team identified and fixed a flaw in the way Revizto handled Single Sign-On (SSO) logins. Under specific conditions, the flaw could have allowed someone with an active Revizto subscription, who also controlled an Identity Provider, to sign in as a different user — even one protected by two-factor authentication — and view or change parts of that user's profile. Revizto is not aware of any exploitation of this vulnerability. The fix is deployed on Revizto's servers across all twelve production regions worldwide. No action is required from customers or end users. Revizto found no evidence that this issue was used to access any account, and is publishing this advisory to keep customers informed in line with its security commitments. Description What happened When a customer uses Single Sign-On (SSO) to log into Revizto, the customer's Identity Provider (the corporate login service, for example Okta, Microsoft Entra ID, or a similar product) sends Revizto a digitally-signed message that says, in effect, "this person has been authenticated, you can let them in." Revizto correctly checked that the message itself was valid. However, when Revizto then looked up the user account to log in, it searched across the whole region by email address — without confirming that the user belonged to the same customer organisation whose SSO setup had produced the message. In a narrow set of conditions, that gap could have allowed someone who controlled their own Identity Provider, and who knew a user's email address, to start a Revizto session as that other user. Because the session was created through SSO, two-factor authentication would not get a chance to challenge the attempt. Once such a session was established, account-scoped business data (projects, issues, models) was still protected by a separate check and was not exposed. However, a smaller set of user-level actions — viewing the user's personal details, editing their profile, or disconnecting their third-party Common Data Environment (CDE) integrations — remained reachable until the fix was deployed. Technical Detail (for security teams) After SAML assertion validation, the authentication service performed a region-wide email lookup of the user without enforcing that the resolved user belonged to the account that owned the SAML authentication method. The post-login spEntityId check correctly blocked account-scoped business data, but user-level endpoints that did not depend on MemberLogic remained accessible to the cross-account session. The SAML flow bypassed two-factor authentication. The configuration wantAssertionsSigned: false reduced the cost of forging assertions where the target Identity Provider did not require them to be signed. Potential Impact If exploited, this vulnerability could result in gaining access to: A user's personal information (first name, last name, email, organization memberships, project names). Modifying the user's profile attributes. Removing the user's OAuth integration connections to third-party Common Data Environments (CDEs). Obtaining a password reset token. Note: OAuth access tokens for third-party Common Data Environment (CDE) integrations are stored on the Revizto desktop client and are not retrievable through the affected web session. Detection and Exploitation Known Exploitation Revizto is not aware of any exploitation of this vulnerability. The issue was identified through Revizto's internal threat-modelling programme and confirmed by the in-house Application Security team. A security verification was performed: at the present time, no users in the Revizto database have access to a third-party CDE outside of their own company, and no inbound report, public PoC, or third-party advisory indicates that there has been any past exploitation of the vulnerability. Detection Guidance No customer/user detection action is required. Customers wishing to review specific historical activity may contact Revizto Support for assisted review. Mitigation and Remediation Immediate Action No customer/user action is required. Revizto has deployed a server-side fix, which is effective for all customers. Permanent Fix The authentication service now enforces an end-to-end binding between the email submitted at SSO initiation and the identity resolved from the SAML assertion. Cross-account session establishment is no longer possible through this code path. The fix has been deployed to all twelve (12) Revizto-managed production regions: USA (Virginia), Canada (Quebec), Ireland (Dublin), United Kingdom (London), Switzerland (Zurich), United Arab Emirates (Abu Dhabi), Singapore (Singapore), Japan (Tokyo), Australia (Sydney), Brazil (São Paulo), China (Shanghai), and Kingdom of Saudi Arabia (Riyadh). Deployment completed: 13-05-2026 Recommendations As a matter of general best practice, we recommend Revizto customers reconnect their CDEs into Revizto, which will refresh the OAuth token. References Internal references: INFOSEC-1516, WEB-18584, WEB-17260 CVSS 3.1 vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N No corresponding public CVE has been assigned; the vulnerability is internal to the Revizto Solution. Contact Information For questions regarding this advisory, please contact the Security Team at [email protected]. For technical assistance with your tenant, please contact [email protected]. Security RVZ-SA-2026-001: Important Information on Axios npm Supply Chain Compromise (plain-crypto-js RAT) Published April 1, 2026 Related to Revizto Vulnerability Advisory ID: N/A — No advisory issued (Revizto not impacted) Severity: CVSS Score 9.8 (Critical) — Impact: Remote Code Execution via supply chain compromise Affected Product/Service/Component: npm packages [email protected], [email protected], [email protected] (third-party open-source) Impacted Versions: axios 1.14.1, axios 0.30.4 Mitigated Versions: axios 1.14.0 and earlier; axios >=1.14.2 (once published by maintainers) Date Published: 01-Apr-2026 Last Updated: 01-Apr-2026 SUMMARY On 2026-03-31, a supply chain attack was identified targeting the widely used axios npm package. An attacker (attributed to UNC1069 / GOLDEN CHOLLIMA, a North Korea-linked threat actor) hijacked a maintainer account and published compromised versions 1.14.1 and 0.30.4. These versions include a postinstall script that installs [email protected], which drops a cross-platform Remote Access Trojan (RAT) targeting Linux, macOS, and Windows. Revizto has conducted a thorough investigation and confirmed that the Revizto Solution, infrastructure, and endpoints are not affected by this vulnerability. DESCRIPTION The compromised axios versions execute a malicious postinstall script during npm install that downloads and installs [email protected]. This package deploys a cross-platform RAT capable of providing persistent remote access to the compromised host. The attack targets any development or production environment that resolved the affected axios versions via npm between 2026-03-31 and the time of package removal. POTENTIAL IMPACT No impact to Revizto. Our investigation confirmed: No compromised packages were installed on any Revizto endpoint, build server, or production system. No malicious process execution, file writes, or DNS activity associated with plain-crypto-js was detected across our fleet. Proactive remediation was applied: all Revizto function apps that depend on axios have been pinned to the verified safe version 1.14.0 with exact version locks (removing range specifiers) to prevent automatic resolution to compromised versions. DETECTION AND EXPLOITATION Known Exploitation: Active exploitation in the wild via npm package resolution. The compromised versions have been reported to npm for removal. Detection Guidance: Organizations should audit their node_modules directories and package-lock.json files for references to [email protected], [email protected], or plain-crypto-js. Endpoint detection logs should be reviewed for postinstall script execution spawning unexpected child processes from node. Revizto's investigation included: CrowdStrike Falcon NG-SIEM queries across all managed endpoints for process execution, file writes, and DNS activity matching the IOCs Review of all npm postinstall activity on developer and build hosts between 2026-03-28 and 2026-04-01 Verification that no CrowdStrike detections or incidents are associated with these IOCs Pinning of axios dependencies to known-safe versions across all five Azure Sentinel function apps MITIGATION AND REMEDIATION No action is required by Revizto customers. The Revizto Solution was not affected. For awareness, the following defensive measures have been implemented internally: All axios dependencies pinned to exact version 1.14.0 across function apps Ongoing monitoring via CrowdStrike Falcon and LogScale for any IOCs related to this campaign Continuous threat intelligence monitoring for related activity from GOLDEN CHOLLIMA / UNC1069 USER ADVICE No action is required. This bulletin is published for transparency and to anticipate any queries from customers or partners regarding this widely reported supply chain attack. Revizto continues to monitor the situation and will publish updates if the threat landscape changes. REFERENCES npm advisory for axios (pending official CVE assignment) CrowdStrike Intelligence: GOLDEN CHOLLIMA threat actor profile Revizto internal investigation: CrowdStrike Falcon NG-SIEM hunt — 01-Apr-2026 CONTACT INFORMATION For security-related questions about this bulletin, please contact our Security team at: [email protected]