Executive brief
Combodo iTop is a web-based IT service management platform used by organizations to track and manage IT infrastructure and services. An improper access control flaw in versions before 3.2.3 allows authenticated users with limited permissions to access documents without proper authorization checks, potentially exposing sensitive business data and IT configuration information to unauthorized personnel.
Technical details
The vulnerability is an improper access control issue in ajax.render.php and ajax.document.php that fails to validate user permissions when accessing documents. Unlike the Attachment class which enforces proper rights checks, the document handling code allows direct access without verifying the current user's authorization level. An attacker with valid iTop credentials (low-privilege user) can bypass permission controls to retrieve documents they should not have access to. The vulnerability requires network access to the iTop application and valid authentication, but no additional user interaction. The fix, implemented in versions 3.2.3 and 3.3.0, applies the same safety checks to documents that the Attachment class uses.
Affected products
- Combodo iTop <3.2.3
Timeline
- 2026-08-21: disclosed: CVE-2026-34836 published
- 2026-03-30: patched: Fix committed to repository for versions 3.2.3 and 3.3.0