Unauthenticated File Deletion Vulnerability in Combodo iTop ITSM Tool
CVE-2026-34949

6.5MEDIUM

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-34949?

Combodo iTop, a web-based IT service management tool, had a significant security vulnerability whereby unauthenticated users could delete the .readonly file. This file, established during the setup process, is crucial as it prevents unauthorized write actions on iTop instances. The vulnerability has been addressed in version 3.2.3, underscoring the importance of updating to the latest version to maintain the security and integrity of your iTop environment.

Affected Version(s)

iTop < 3.2.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.