Junglewise Threat Intelligence

CVE-2026-31936: Combodo iTop unauthorized access via search operation

CVE-2026-31936 · Severity: high · CVSS 8.8 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management tool used by organizations to track and manage IT assets, incidents, and services. Prior to version 3.2.3, authenticated users can bypass permission checks in the search functionality to access sensitive object information they are not authorized to view, potentially exposing confidential IT infrastructure and business data.

Technical details

The vulnerability exists in the search operation handler (ajax.render.php) where user permission checks were not properly enforced. An authenticated attacker with low privileges can craft search requests that return unauthorized object information by exploiting insufficient authorization validation. The vulnerability requires network access and valid user credentials (low privilege account) but no user interaction. An attacker can achieve confidentiality, integrity, and availability impact by accessing, modifying, or disrupting data visibility. The fix was implemented in version 3.2.3 and 3.3.0 by adding proper permission validation in the AjaxRenderController search operation.

Affected products

  • Combodo iTop prior to 3.2.3

Timeline

  • 2026-08-10: disclosed
  • 2026-08-21: patched: Version 3.2.3 and 3.3.0 released

References

Related threats