High severity7.5NVD Advisory· Published Aug 21, 2026
CVE-2026-27462
CVE-2026-27462
Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.