Reflected XSS Vulnerability in Combodo iTop IT Service Management Tool
CVE-2026-30890

8HIGH

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-30890?

Combodo iTop, a web-based IT service management solution, is affected by a reflected Cross-Site Scripting (XSS) vulnerability present in the synchro import script prior to version 3.2.3. This security flaw could allow attackers to inject malicious scripts, compromising the security of users interacting with the impacted application. The issue has been addressed in version 3.2.3, where adequate security measures have been implemented to mitigate this risk effectively.

Affected Version(s)

iTop < 3.2.3

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.