CVE-2026-34949: Combodo iTop: Unauthenticated user can delete .readonly file
Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from performing write actions. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Combodo iTop instances running versions prior to 3.2.3 are affected. The issue is reachable remotely without authentication.
What does an attacker need to exploit the issue?
No credentials or user interaction are required. An attacker only needs network access to a vulnerable iTop instance.
What is the practical impact of deleting the .readonly file?
The .readonly file is created during setup to prevent write actions. Deleting it can remove that protection and allow write actions that the file was intended to block.
How can the issue be remediated?
Upgrade Combodo iTop to version 3.2.3, which fixes the issue.