CVE-2026-34836: Combodo iTop: Improper access control in ajax.render.php and ajax.document.php
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the iTop instance and low-privileged authenticated access. No user interaction is required.
What information could be exposed?
The vulnerability permits access to documents without enforcing the affected user's permissions. The stated impact is high confidentiality impact, with no integrity or availability impact.
Which deployments need remediation?
Combodo iTop versions prior to 3.2.3 are affected. Upgrade to version 3.2.3, which fixes the access-control checks in the affected AJAX endpoints.