Combodo iTop: Critical RCE and XSS Vulnerabilities Disclosed Together
Combodo iTop faces disclosure of three vulnerabilities, including critical RCE and XSS flaws, all patched in version 3.2.3.

Key findings
- Combodo iTop: Three vulnerabilities, including critical RCE and XSS, disclosed on August 24, 2026.
- CVE-2026-39975 allows unauthenticated users to delete a critical file, leading to code execution.
- CVE-2026-40877 is a PHP object injection flaw in user preferences, also leading to RCE.
- CVE-2026-30864 is a reflected XSS vulnerability in the dashboard revert functionality.
- All disclosed vulnerabilities are fixed in iTop version 3.2.3.
On August 24, 2026, a batch of three vulnerabilities was disclosed for Combodo's iTop IT service management tool. The vulnerabilities, all fixed in version 3.2.3, include a critical unauthenticated file deletion flaw, a high-severity PHP object injection vulnerability, and a high-severity reflected cross-site scripting (XSS) issue. These disclosures highlight potential security weaknesses in the web-based platform.
The most severe vulnerability, CVE-2026-39975, allowed unauthenticated users to delete a critical .readonly file. This file is essential for preventing write actions during the iTop setup process. By deleting it, an attacker could potentially gain code execution capabilities on the affected instance.
Another significant vulnerability, CVE-2026-30864, is a reflected cross-site scripting (XSS) flaw within the dashboard revert functionality. This type of vulnerability can be exploited to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking or other malicious activities.
Additionally, CVE-2026-40877, a PHP object injection vulnerability, was discovered in the user preference functionality. This vulnerability, if exploited, could also lead to remote code execution, posing a serious threat to the integrity and confidentiality of the iTop system.
All three vulnerabilities were addressed in iTop version 3.2.3. Users are strongly advised to update to this version to mitigate the risks associated with these security flaws. The coordinated disclosure of these issues on the same day indicates a focused effort to address multiple security concerns within the iTop platform.
The timely patching of these vulnerabilities is crucial for organizations using iTop to manage their IT services. Failure to update could leave systems exposed to remote code execution and cross-site scripting attacks, compromising sensitive IT service management data and operations.
The vulnerabilities disclosed are:
- CVE-2026-39975: Unauthenticated deletion of
.readonlyfile leading to code execution. - CVE-2026-40877: PHP object injection in user preferences, potentially leading to remote code execution.
- CVE-2026-30864: Reflected XSS in dashboard revert functionality.
All issues were resolved in iTop version 3.2.3. It is imperative for all users to upgrade to this patched version to secure their iTop instances against these threats.