CVE-2026-30866: Combodo iTop: Insecured access to uploaded images via sniffed url
Published Aug 21, 2026
·Updated
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
Affected Software
1 affected component
Combodo iTop<3.2.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Aug 21, 2026
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. Version 3.2.3 fixes the issue.
2
What does an attacker need to access uploaded images?
An attacker does not need authentication, but must obtain or sniff the URL of an uploaded sensitive image. The available information does not describe other prerequisites or mitigations.