CVE-2026-27490
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Combodo | iTop | < 3.2.3 | affected |
Weaknesses
- CWE-331: CWE-331: Insufficient Entropy
- CWE-330: CWE-330: Use of Insufficiently Random Values
References
- https://github.com/Combodo/iTop/security/advisories/GHSA-3jr5-rqmx-97gc
- http://github.com/Combodo/iTop/commit/9c39efd9af53a1deeb578133eff7333a7b8816b0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.