CVE-2026-40877

8.7

Combodo · iTop

Combodo iTop is vulnerable to deserialization of untrusted data and code injection, potentially allowing authenticated users with low privileges to execute arbitrary code.

Executive summary

A vulnerability in Combodo iTop allows authenticated attackers to perform code injection via deserialization, posing a significant risk to system integrity.

Vulnerability

The application is susceptible to deserialization of untrusted data and improper control of code generation (CWE-502, CWE-94). An authenticated attacker with low privileges can trigger these flaws to inject and execute arbitrary code on the underlying server.

Business impact

Successful exploitation allows an attacker to achieve remote code execution, leading to full system compromise. Given the CVSS score of 8.7, this is a high-severity risk that could result in the theft of sensitive IT service management data, unauthorized administrative access, and potential lateral movement within the corporate network.

Remediation

Immediate Action: Upgrade all instances of iTop to version 3.2.3 or higher immediately.

Proactive Monitoring: Review web server access logs for unusual requests containing serialized objects or patterns associated with code injection attempts.

Compensating Controls: Implement a Web Application Firewall (WAF) to filter out malicious payloads targeting deserialization endpoints, although this should be treated as a temporary measure until patching is complete.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a critical threat to the security of your IT service management infrastructure. Security teams should prioritize the update to version 3.2.3 to eliminate the deserialization and injection vectors. Failure to patch may allow attackers to gain persistent access to the host environment.

More Combodo CVEs