Sensitive Information Disclosure in Combodo iTop IT Service Management Tool
CVE-2026-33333

3.5LOW

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-33333?

The Combodo iTop IT service management tool experienced a vulnerability prior to version 3.2.3 that resulted in sensitive information being disclosed through error messages. This exposure can potentially allow unauthorized individuals to gain insights into the system's internal structure and configuration, posing a risk to organizational data security. The issue has been addressed in the latest version, emphasizing the importance of keeping software up to date to mitigate potential risks.

Affected Version(s)

iTop < 3.2.3

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.