Missing Authorization Vulnerability in Combodo iTop
CVE-2026-108717
5.3MEDIUM
What is CVE-2026-108717?
The vulnerability in Combodo iTop versions 3.1.0 through 3.3.0 resides in the LinkSetController.php file, where authenticated console users can exploit a failure in authorization checks. By providing arbitrary class and key parameters, attackers may bypass profile grants, allowing them to invoke sensitive operations such as deleting objects, clearing external keys, and reading object attributes without proper authorization. This flaw could lead to unauthorized access and manipulation of data, impacting the integrity and confidentiality of critical information.
Affected Version(s)
iTop 3.1.0 <= 3.3.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
