Executive brief
Combodo iTop is a web-based IT service management platform used by organizations to manage IT services and infrastructure. The login page logo HTML title attribute exposes the complete iTop version number, allowing unauthenticated attackers to identify which version is running and potentially target known vulnerabilities in that specific version. This information disclosure could facilitate reconnaissance for further attacks.
Technical details
The vulnerability is an information disclosure (CWE-200) caused by the HTML title attribute of the logo element on the login page containing the full iTop version string. The vulnerable code used Dict::Format('UI:iTopVersion:Short', ITOP_APPLICATION, ITOP_VERSION) to populate this attribute, which is exposed to unauthenticated users during the login page load. The attack vector is network-based with no authentication or user interaction required. An attacker can view the page source or inspect HTML elements to retrieve the version information. The issue was patched in version 3.2.3 and 3.3.0 by removing the version attribute and making the logo title customizable through configuration.
Affected products
- Combodo iTop prior to 3.2.3
Timeline
- 2026-08-21: disclosed: CVE-2026-27463 published
- 2026-02-18: patched: Fix committed (version 3.2.3 and 3.3.0)