Combodo iTop, a web-based IT service management tool, is vulnerable to PHP object injection in its user preference functionality prior to version 3.2.3. This vulnerability can be exploited to achieve remote code execution (RCE). The flaw resides in how user preferences are handled, allowing attackers to inject malicious PHP objects. The issue has been assigned CVE-2026-40877 and is rated high criticality. A fix has been released in iTop version 3.2.3. Organizations using iTop should upgrade immediately to mitigate the risk of remote compromise. No specific threat actors or active exploitation have been mentioned in the article.