Combodo iTop: 18 Vulnerabilities Including Auth Bypass and XSS Disclosed Together
Combodo iTop: 18 vulnerabilities disclosed together, patched in version 3.2.3, including critical auth bypass and XSS flaws.

Key findings
- 18 vulnerabilities in Combodo iTop disclosed on August 21, 2026, all fixed in version 3.2.3.
- High-severity flaws include authentication bypass, arbitrary file execution, and unauthorized data access.
- Multiple Reflected Cross-Site Scripting (XSS) vulnerabilities affect various iTop components.
- Critical patches address issues ranging from file deletion to user enumeration and information disclosure.
- Users are urged to update to iTop 3.2.3 to mitigate these widespread security risks.
On August 21, 2026, a batch of 18 vulnerabilities was disclosed for Combodo's iTop IT service management tool, all fixed in version 3.2.3. The disclosures cluster around a single release, highlighting a range of security weaknesses from critical authentication bypasses to information disclosure. The sheer volume and severity of these vulnerabilities underscore the importance of timely patching for iTop instances.
Several vulnerabilities revolve around improper access control and authentication bypasses, allowing unauthorized users to access sensitive data or perform actions they should not be able to. CVE-2026-34741, a high-severity authentication bypass, permits unauthenticated remote attackers to execute arbitrary PHP files on new iTop instances. Similarly, CVE-2026-34948 addresses an issue where silo access checks were not properly applied to classes in the SELECT clause of OQL queries, potentially exposing data. CVE-2026-31936 also falls into this category, enabling users to access unauthorized object information through search operations. CVE-2026-30865 and CVE-2026-27490, both rated high, involve unauthenticated access to sensitive uploaded files via sniffed URLs and weak protection for inline images, respectively.
Reflected Cross-Site Scripting (XSS) vulnerabilities are another prominent theme within this batch. CVE-2026-33240, a high-severity flaw, exists in the foreign key search criteria API. Other XSS vulnerabilities include CVE-2026-31880 in the universal search, CVE-2026-31803 in pages/tagadmin.php, CVE-2026-30890 in the synchro import script, CVE-2026-30826 in the testing OQL query functionality, and CVE-2026-30819 in the dashboard revert functionality. CVE-2026-30865 also relates to XSS in dashboard save functionality.
Other notable vulnerabilities include CVE-2026-34949, a medium-severity flaw allowing unauthenticated users to delete a critical setup file that prevents write actions, potentially reverting an instance to an unconfigured state. CVE-2026-33047, another medium-severity issue, permits users without write permissions to lock objects. CVE-2026-27462, a high-severity vulnerability, allows for user enumeration through different responses in the password reset mechanism for valid and invalid usernames. Lastly, CVE-2026-33333, a low-severity flaw, involves sensitive information disclosure in error messages, and CVE-2026-27463, a medium-severity issue, reveals the full iTop version in the HTML title attribute of the logo on the login page.
All 18 vulnerabilities were addressed in iTop version 3.2.3. Users are strongly advised to update to this version to mitigate these risks. The simultaneous disclosure of such a large number of vulnerabilities highlights a critical need for diligent security practices and prompt updates within the iTop user community.
The comprehensive nature of these fixes in a single version release suggests a thorough internal review or external audit may have prompted this coordinated patch. Staying current with iTop updates is crucial for maintaining the security and integrity of IT service management data and operations.