CVE-2026-30866

Summary

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

Affected Software

VendorProductVersion RangeStatus
CombodoiTop< 3.2.3affected

Weaknesses

  • CWE-306: CWE-306: Missing Authentication for Critical Function
  • CWE-200: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

References