← Back to overview

Combodo iTop, a web-based IT service management tool, contains a Reflected Cross-Site Scripting (XSS) vulnerability tracked as CVE-2026-30826. The vulnerability exists in the OQL (Object Query Language) query testing functionality. An attacker could exploit this flaw to inject malicious scripts that are reflected back to users, potentially leading to session hijacking, credential theft, or other client-side attacks. The vulnerability affects all versions of iTop prior to 3.2.3. Combodo has addressed the issue in version 3.2.3. A fix was committed to the official GitHub repository and a security advisory was published. Users are strongly advised to upgrade to version 3.2.3 or later to mitigate the risk.

Affected products

  • Combodo iTop

Related CVE's

  • CVE-2026-30826

Categories

  • Enterprise Applications
  • Web Technologies