CVE-2026-33047: Combodo iTop: Object can be locked by a user without write permissions
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with low privileges can exploit it, because the vulnerability requires privileges but does not require write permissions on the target object. The attack can be performed remotely and does not require user interaction.
What is the operational impact?
A user without write permissions can lock an object, which can cause an availability impact by preventing normal work on that object. The supplied severity vector indicates no confidentiality or integrity impact.
Which versions are affected and what fixes it?
Versions prior to 3.2.3 are affected. Upgrade to iTop 3.2.3, which includes the fix.