Junglewise Threat Intelligence

CVE-2026-33240: Combodo iTop reflected XSS in foreign key search

CVE-2026-33240 · Severity: high · CVSS 8.8 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is an IT service management platform used to track IT assets and handle service requests. A reflected cross-site scripting vulnerability in the foreign key search API allows attackers to inject malicious scripts that execute in users' browsers when they click a crafted link, potentially stealing session credentials or performing unauthorized actions within the application.

Technical details

A reflected XSS vulnerability exists in iTop's foreign key search criteria API prior to version 3.2.3. The vulnerability arises from improper handling of user input in search parameters, allowing an attacker to inject JavaScript code that is reflected back to the user without sanitization. The attack requires user interaction (clicking a malicious link) and is network-accessible without requiring authentication. An attacker can craft a malicious URL to steal session tokens, modify data, or perform actions on behalf of the victim user. The issue is fixed in version 3.2.3 and later (3.3.0) through code modernization that properly handles user input.

Affected products

  • Combodo iTop prior to 3.2.3

Timeline

  • 2026-08-21: disclosed
  • 2026-03-18: patched: Fix committed; versions 3.2.3 and 3.3.0 contain the patch

References

Related threats