User Enumeration Vulnerability in Combodo iTop IT Service Management Tool
CVE-2026-27462
7.5HIGH
What is CVE-2026-27462?
Combodo iTop, a web-based IT service management tool, has a vulnerability that allows an attacker to differentiate between valid and invalid usernames through inconsistent responses in the password reset mechanism. This weakness, present prior to version 3.2.3, enables malicious actors to potentially identify valid user accounts, making it crucial to upgrade to the latest version to safeguard against unauthorized access and data breaches. The issue has been rectified in subsequent updates, emphasizing the importance of maintaining software versions.
Affected Version(s)
iTop < 3.2.3
