Junglewise Threat Intelligence

CVE-2026-34741: Combodo iTop authentication bypass in exec.php

CVE-2026-34741 · Severity: high · CVSS 8.6 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management platform used to track and manage IT operations. Prior to version 3.2.3, an unauthenticated attacker can bypass authentication and execute arbitrary PHP files from the production environment directory, allowing complete compromise of the system without requiring any credentials or user interaction.

Technical details

The vulnerability is an authentication bypass in the exec.php file that allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance. The root cause is insufficient authentication checks in exec.php before allowing file execution. The attack vector is network-based with no authentication required, no user interaction needed, and affects production environments. An attacker can achieve arbitrary PHP code execution and data manipulation (high integrity impact). The vulnerability is fixed in iTop versions 3.2.3 and 3.3.0 through the introduction of a configuration option (security.force_login_when_no_delegated_authentication_endpoints_list) to enforce authentication, though this is not the default behavior initially to maintain backward compatibility.

Affected products

  • Combodo iTop prior to 3.2.3

Timeline

  • 2026-08-21: disclosed
  • 2026-03-16: patched: Fix committed to develop branch (PR #835)

References

Related threats