Executive brief
Combodo iTop is a web-based IT service management platform used by organizations to track and manage IT assets and services. An unauthenticated attacker can delete a critical security file (.readonly) that prevents unauthorized modifications to the system, enabling them to perform write operations that should be restricted during locked-down periods. This could allow attackers to modify IT service records, create unauthorized assets, or alter critical system configurations.
Technical details
The vulnerability is an improper access control flaw in the iTop file cleanup mechanism. An unauthenticated user can delete the .readonly file, which is created during the setup process to enforce read-only mode and block write actions. The issue affects iTop versions prior to 3.2.3 and stems from inadequate authentication checks during the cleanup phase. The vulnerability requires network access but no authentication or user interaction; an attacker can directly trigger the deletion via HTTP requests. The fix, available in versions 3.2.3 and 3.3.0, skips the cleanup phase if authentication is incorrect, preventing unauthenticated file manipulation.
Affected products
- Combodo iTop prior to 3.2.3
Timeline
- 2026-08-10: advisory: GitHub security advisory published
- 2026-08-21: patched: Fix available in versions 3.2.3 and 3.3.0