User Enumeration Vulnerability in Combodo iTop IT Service Management Tool
CVE-2026-27462

7.5HIGH

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-27462?

Combodo iTop, a web-based IT service management tool, has a vulnerability that allows an attacker to differentiate between valid and invalid usernames through inconsistent responses in the password reset mechanism. This weakness, present prior to version 3.2.3, enables malicious actors to potentially identify valid user accounts, making it crucial to upgrade to the latest version to safeguard against unauthorized access and data breaches. The issue has been rectified in subsequent updates, emphasizing the importance of maintaining software versions.

Affected Version(s)

iTop < 3.2.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.