Reflected XSS Vulnerability in Combodo iTop IT Service Management Tool
CVE-2026-33240

8.8HIGH

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-33240?

The Combodo iTop IT service management tool was found to have a reflected cross-site scripting (XSS) vulnerability in its foreign key search criteria API prior to version 3.2.3. This vulnerability could potentially allow attackers to inject malicious scripts, compromising user data and security. Users are encouraged to upgrade to the latest version (3.2.3) to mitigate this issue and enhance their overall web security.

Affected Version(s)

iTop < 3.2.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.