Junglewise Threat Intelligence

CVE-2026-27462: Combodo iTop user enumeration in password reset

CVE-2026-27462 · Severity: high · CVSS 7.5 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management platform used to manage IT assets, services, and incidents. The application returns different responses when processing password reset requests for valid versus invalid usernames, allowing attackers to enumerate valid user accounts without authentication. This can be used to compile a list of legitimate usernames for targeted attacks such as brute-force login attempts or phishing campaigns.

Technical details

This vulnerability is a user enumeration weakness (CWE-204: Observable Response Discrepancy) in iTop's password reset mechanism. The application returns distinguishable responses depending on whether a submitted username exists in the system, allowing an unauthenticated attacker on the network to systematically identify valid accounts. The vulnerability requires no authentication or user interaction and is exploitable via network access. The fix, implemented in version 3.2.3, standardizes password reset error messages so valid and invalid usernames receive identical responses, preventing information disclosure.

Affected products

  • Combodo iTop <3.2.3

Timeline

  • 2026-08-21: disclosed
  • 2026-02-19: patched: Fixed in versions 3.2.3 and 3.3.0

References

Related threats