CVE-2026-40877: Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. Version 3.2.3 contains the fix.
What access does an attacker need to exploit this issue?
The vector indicates network-reachable exploitation with low attack complexity, but the attacker must have low-level privileges and user interaction is required. Successful exploitation can lead to remote code execution.
What should teams do if they are running an affected version?
Upgrade Combodo iTop to version 3.2.3. The supplied information does not identify a workaround or mitigation for systems that cannot be patched immediately.