Missing Authorization Vulnerability in Combodo iTop
CVE-2026-108717

5.3MEDIUM

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108717?

The vulnerability in Combodo iTop versions 3.1.0 through 3.3.0 resides in the LinkSetController.php file, where authenticated console users can exploit a failure in authorization checks. By providing arbitrary class and key parameters, attackers may bypass profile grants, allowing them to invoke sensitive operations such as deleting objects, clearing external keys, and reading object attributes without proper authorization. This flaw could lead to unauthorized access and manipulation of data, impacting the integrity and confidentiality of critical information.

Affected Version(s)

iTop 3.1.0 <= 3.3.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.