Combodo iTop, a web-based IT service management tool, contains a vulnerability prior to version 3.2.3 where inline images accessible without authentication are protected only by a weak 24-bit pseudo-random secret. This weak randomness could allow an attacker to brute-force or predict the secret and gain unauthorized access to inline images. The vulnerability affects all versions of iTop prior to 3.2.3. The issue has been patched in version 3.2.3. The fix is available via a commit on the official GitHub repository. No authentication is required to exploit this vulnerability, increasing its risk surface. Organizations using iTop for IT service management should upgrade to version 3.2.3 immediately. The vulnerability is tracked as CVE-2026-27490 and has a GitHub Security Advisory associated with it.