High severity8.7NVD Advisory· Published Aug 24, 2026· Updated Sep 9, 2026
CVE-2026-40877
CVE-2026-40877
Description
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- Combodo iTop: Critical RCE and XSS Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 24, 2026