Junglewise Threat Intelligence

CVE-2026-39975: Combodo iTop remote code execution via unsafe eval

CVE-2026-39975 · Severity: info · CVSS 9.4 · Published 2026-08-24

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management platform used by organizations to track and manage IT infrastructure and services. A vulnerability in iTop's external authentication variable handling allows privileged users to execute arbitrary code on the server through unsafe use of PHP's eval() function. An attacker with administrative or configuration-editing privileges could exploit this to gain complete control over the iTop instance and potentially the underlying infrastructure.

Technical details

The vulnerability is an unsafe eval vulnerability in the ext_auth_variable configuration parameter. When processing external authentication settings, iTop fails to properly validate or sanitize the ext_auth_variable value before passing it to eval(), allowing arbitrary PHP code execution. The attack requires high-level privileges (administrative access) and network connectivity to the iTop instance. An attacker with config editor access can inject malicious code that will be executed with the privileges of the web server process, leading to complete system compromise. The issue is fixed in iTop versions 3.2.3 and 3.3.0 by implementing whitelisting of allowed ext_auth_variable values.

Affected products

  • Combodo iTop prior to 3.2.3

Timeline

  • 2026-08-10: disclosed: GitHub advisory published
  • 2026-08-24: patched: NVD entry published; fix available in versions 3.2.3 and 3.3.0

References

Related threats