CVE-2026-31936: Combodo iTop: Unauthorized access to object information via search operation
Published Aug 21, 2026
·Updated
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.
Affected Software
1 affected component
Combodo iTop<3.2.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Aug 21, 2026
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. Version 3.2.3 includes the fix.
2
What level of access does an attacker need?
The vulnerability requires low-privileged access to iTop. It can be exploited over the network without user interaction.
3
What is the potential impact?
A low-privileged user may obtain unauthorized object information through the search operation. The published severity vector also rates confidentiality, integrity, and availability impact as high.