CVE-2026-27463: Combodo iTop: Version disclosure via login page logo
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. The issue is present on the login page, where the logo's HTML title attribute exposes the complete iTop version.
Does exploitation require authentication or user interaction?
No. The issue is remotely accessible with low attack complexity and requires neither privileges nor user interaction.
What is the practical impact?
An attacker can learn the exact installed iTop version. The reported impact is limited to information disclosure; no integrity or availability impact is specified.
How can I determine whether an instance is vulnerable?
Inspect the login page's logo HTML element and check its title attribute. An instance is affected if it exposes the complete iTop version and is running a version earlier than 3.2.3.
What remediation is available?
Upgrade Combodo iTop to version 3.2.3, which fixes the version disclosure.