CVE-2026-30890
8.0Combodo · iTop
Combodo iTop is susceptible to a cross-site scripting vulnerability that allows an authenticated attacker to inject arbitrary scripts into the application.
Executive summary
An authenticated cross-site scripting vulnerability in Combodo iTop poses a significant risk of session hijacking and unauthorized administrative actions.
Vulnerability
This vulnerability is an instance of CWE-79, involving improper neutralization of input during web page generation. An authenticated attacker with low privileges can trigger this flaw through user interaction.
Business impact
Exploitation of this vulnerability may allow an attacker to gain unauthorized access to sensitive information or perform unintended actions within the IT service management environment. With a CVSS score of 8.0, the risk of data compromise and loss of system integrity is substantial, particularly if the attacker targets high-privilege user sessions.
Remediation
Immediate Action: Update the iTop installation to version 3.2.3 or later to remediate the underlying input validation failure.
Proactive Monitoring: Monitor user activity logs for signs of script injection or anomalous behavior originating from authenticated accounts.
Compensating Controls: Implement strict Content Security Policy (CSP) headers to restrict the execution of unauthorized scripts within the browser.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for high-impact compromise, administrators must treat this as a priority update. Ensure all instances are patched to version 3.2.3 immediately to secure the application against this vector.