CVE-2026-40877: Combodo Itop
High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
Affected products
- Combodo Itop: before 3.2.3 (fixed in 3.2.3)
Published 2026-08-24. Last modified 2026-09-09.