Authentication Bypass in Combodo iTop IT Service Management Tool
CVE-2026-34741
8.6HIGH
What is CVE-2026-34741?
Combodo iTop is a web-based IT service management tool that was susceptible to an authentication bypass vulnerability. This flaw allowed unauthenticated remote attackers to execute arbitrary PHP files located in the env-production directory from a new iTop instance deployed in a production environment. The issue has been addressed in version 3.2.3, which mitigates this serious risk by implementing enhanced authentication measures and controls.
Affected Version(s)
iTop < 3.2.3
