CVE-2026-34741: Combodo iTop: Authentication bypass in exec.php allows PHP file execution
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects new Combodo iTop instances running in the production environment before version 3.2.3. The vulnerable files are in the env-production directory.
What does an attacker need to exploit this issue?
An attacker can exploit the authentication bypass remotely without credentials or user interaction. Successful exploitation allows execution of arbitrary PHP files from the env-production directory.
What version fixes the vulnerability?
Combodo iTop version 3.2.3 fixes this issue.