CVE-2026-27490: Combodo iTop: Weak secret generation for inline image
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Who can access affected inline images?
Inline images configured to be accessible without authentication are exposed. The vulnerability affects iTop versions prior to 3.2.3.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. They need network access to the affected iTop instance and must guess the weak 24-bit pseudo-random secret protecting an inline image.
What should teams do to remediate the issue?
Upgrade Combodo iTop to version 3.2.3, which fixes the weak secret generation.