← Back to overview

CVE-2026-30866 affects Combodo iTop, a web-based IT service management tool. Prior to version 3.2.3, unauthenticated users could access uploaded sensitive files by using a sniffed URL, representing an unauthorized information disclosure vulnerability. The flaw requires no authentication to exploit, making it particularly dangerous in exposed environments. The issue has been remediated in iTop version 3.2.3. A patch commit is available on GitHub along with a security advisory. Organizations using iTop versions prior to 3.2.3 should upgrade immediately to mitigate the risk of sensitive data exposure.

Affected products

  • Combodo iTop

Related CVE's

  • CVE-2026-30866

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Identity & Access
  • Web Technologies