Junglewise Threat Intelligence

CVE-2026-34948: Combodo iTop access control bypass in OQL joins

CVE-2026-34948 · Severity: high · CVSS 7.7 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management tool that manages assets, incidents, and other IT data. A flaw in the access control logic allows authenticated users to bypass security restrictions (silos) when querying data via OQL by joining tables not explicitly listed in the SELECT clause, potentially exposing sensitive business information that should be restricted from viewing.

Technical details

The vulnerability is an access control bypass (CWE-200) in iTop's OQL query processor. Only classes directly listed in the SELECT clause were protected by silo access checks, leaving joined classes accessible via JOIN, UNION, or IN clauses without validation. An authenticated attacker with low privileges can craft OQL queries that reference restricted data through table joins to bypass confidentiality controls. The fix, available in version 3.2.3 and 3.3.0, applies access checks to all classes in JOIN, UNION, and IN clauses when the security.disable_joined_classes_filter configuration parameter is set to false (the secure default).

Affected products

  • Combodo iTop before 3.2.3

Timeline

  • 2026-08-21: disclosed
  • 2026-03-31: patched: Fix committed; versions 3.2.3 and 3.3.0 include the patch

References

Related threats