PT-2026-79489 · Comodo · Itop

CVE-2026-33240

·

Published

2026-08-21

·

Updated

2026-08-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 3.2.3
Description Combodo iTop is a web-based IT service management tool. A reflected cross-site scripting (XSS) flaw exists in the foreign key search criteria API, where user-supplied input is not properly sanitized before being returned in the HTTP response. This allows an attacker to inject arbitrary client-side scripts that execute in the victim's browser, potentially leading to session hijacking, data exfiltration, or website defacement. The attack typically requires network connectivity to the application and social engineering to trick an authenticated user into clicking a malicious link.
Recommendations Upgrade to version 3.2.3 or later. Restrict access to the foreign key search criteria API to minimize the risk of exploitation until the upgrade is complete.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33240
GHSA-5HW5-FVW4-55P4

Affected Products

Itop