Executive brief
Combodo iTop is a web-based IT service management platform used to manage IT assets, services, and incidents. The application returns different responses when processing password reset requests for valid versus invalid usernames, allowing attackers to enumerate valid user accounts without authentication. This can be used to compile a list of legitimate usernames for targeted attacks such as brute-force login attempts or phishing campaigns.
Technical details
This vulnerability is a user enumeration weakness (CWE-204: Observable Response Discrepancy) in iTop's password reset mechanism. The application returns distinguishable responses depending on whether a submitted username exists in the system, allowing an unauthenticated attacker on the network to systematically identify valid accounts. The vulnerability requires no authentication or user interaction and is exploitable via network access. The fix, implemented in version 3.2.3, standardizes password reset error messages so valid and invalid usernames receive identical responses, preventing information disclosure.
Affected products
- Combodo iTop <3.2.3
Timeline
- 2026-08-21: disclosed
- 2026-02-19: patched: Fixed in versions 3.2.3 and 3.3.0