Weak Secret Protection in Combodo iTop Web-Based IT Service Management Tool
CVE-2026-27490
7.5HIGH
What is CVE-2026-27490?
Combodo iTop, a web-based IT service management tool, has a vulnerability in versions prior to 3.2.3, where inline images that are accessible without authentication were protected by a weak 24-bit pseudo-random secret. This flaw potentially allows unauthorized users to access sensitive images within the application. The issue has been addressed in version 3.2.3.
Affected Version(s)
iTop < 3.2.3
