CVE-2026-30826: Combodo iTop: Reflected XSS in run_query.php
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access and must induce a user to interact with a crafted request in the testing OQL query functionality. The attack is network-accessible and does not require elevated privileges.
Which deployments are affected?
iTop versions prior to 3.2.3 are affected where the testing OQL query functionality is available. Version 3.2.3 contains the fix.
What should teams do if they cannot immediately upgrade?
The provided information does not identify a workaround. Restrict access to the testing OQL query functionality to trusted users until upgrading to 3.2.3 is possible.