Junglewise Threat Intelligence

CVE-2026-40877: Combodo iTop PHP object injection in user preferences

CVE-2026-40877 · Severity: high · CVSS 8.7 · Published 2026-08-24

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management platform used to track and manage IT assets and services. A PHP object injection vulnerability in the user preference functionality allows authenticated users to execute arbitrary code on the server, potentially compromising the entire system and exposing sensitive IT data.

Technical details

The vulnerability is a PHP object injection flaw in iTop's user preference functionality that occurs prior to version 3.2.3. It requires network access and an authenticated user account (low privilege level), with user interaction required to trigger the exploit. An attacker with valid credentials can craft malicious serialized PHP objects that, when deserialized during preference processing, execute arbitrary code on the server. This leads to remote code execution with the privileges of the web server process. The issue has been patched in versions 3.2.3 and 3.3.0.

Affected products

  • Combodo iTop prior to 3.2.3

Timeline

  • 2026-08-10: disclosed
  • 2026-08-24: patched: Fixed in versions 3.2.3 and 3.3.0

References

Related threats