CVE-2026-39975: Combodo iTop: Remote code execution using external auth variable value
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are affected?
iTop versions prior to 3.2.3 are affected. The issue applies to instances where the setup-created .readonly file is present and relied upon to prevent write actions.
Does exploitation require authentication?
No. The vulnerability allows unauthenticated users to delete the .readonly file, which can lead to code execution.
What should teams do if they cannot patch immediately?
Ensure unauthenticated users cannot reach the affected iTop instance or otherwise prevent them from deleting the .readonly file. Upgrade to version 3.2.3 as soon as possible.