CVE-2026-34741

8.6

Combodo · iTop

A missing authentication vulnerability in Combodo iTop allows unauthenticated attackers to interact with critical functions, potentially leading to unauthorized data access or system manipulation.

Executive summary

Combodo iTop is affected by a critical missing authentication vulnerability that permits unauthenticated attackers to perform unauthorized operations.

Vulnerability

This vulnerability is caused by missing authentication for critical functions (CWE-306). It allows an unauthenticated remote attacker to bypass security controls and interact with sensitive application features.

Business impact

With a CVSS score of 8.6, this vulnerability poses a severe threat to the integrity and confidentiality of IT service management data. Unauthorized access could result in the exposure of sensitive infrastructure details or the modification of service records, potentially impacting overall business operations.

Remediation

Immediate Action: Upgrade Combodo iTop to version 3.2.3 or the latest available stable release to resolve the authentication bypass.

Proactive Monitoring: Review application access logs for unusual administrative activity or requests originating from unexpected IP addresses.

Compensating Controls: Restrict access to the iTop instance to known, trusted networks using IP allowlisting or VPN requirements until the patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized access to critical IT service data, immediate remediation is required. Organizations should prioritize updating their iTop instances and auditing logs for any signs of unauthorized interaction.

More Combodo CVEs