High severity7.5NVD Advisory· Published Aug 21, 2026· Updated Sep 9, 2026
CVE-2026-30866
CVE-2026-30866
Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
1- Combodo iTop: 18 Vulnerabilities Including Auth Bypass and XSS Disclosed TogetherVypr Intelligence · Aug 21, 2026