Reflected XSS Vulnerability in iTop IT Service Management Tool by Combodo
CVE-2026-30864

8.9HIGH

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-30864?

Combodo iTop is a web-based IT service management solution that has a vulnerability in its dashboard revert functionality, allowing reflected cross-site scripting (XSS) attacks. This flaw could enable an attacker to inject malicious scripts into the web application, impacting user sessions and potentially compromising sensitive user data. The vulnerability was addressed in version 3.2.3, emphasizing the importance of updating to maintain security.

Affected Version(s)

iTop < 3.2.3

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.