PHP Object Injection Vulnerability in Combodo iTop IT Service Management Tool
CVE-2026-40877
8.7HIGH
What is CVE-2026-40877?
Combodo iTop, a web-based IT service management tool, is susceptible to a PHP object injection vulnerability in its user preference functionality. This flaw allows attackers to execute arbitrary code remotely, which can jeopardize the security of affected systems. The vulnerability has been addressed in version 3.2.3, and users are encouraged to upgrade to this version or later to mitigate the risk. For detailed information on the fix, refer to the official advisory link.
Affected Version(s)
iTop < 3.2.3
