CVE-2026-33333: Combodo iTop: Information disclosure in ajax.render.php
Published Aug 21, 2026
·Updated
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.
Affected Software
1 affected component
Combodo iTop<3.2.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Aug 21, 2026
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. The issue is fixed in version 3.2.3.
2
What access and interaction does exploitation require?
The supplied CVSS vector indicates that the attack can be performed over the network with low complexity, but requires low-level privileges and user interaction. The stated impact is limited to confidentiality.
3
How can I determine whether my instance is affected?
Check the installed iTop version. Instances running a version earlier than 3.2.3 should be considered affected.