Combodo iTop, a web-based IT service management tool, contains a Reflected Cross-Site Scripting (XSS) vulnerability in the file pages/tagadmin.php. The vulnerability affects versions prior to 3.2.3 and has been assigned CVE-2026-31803. An attacker could exploit this flaw to inject malicious scripts into web pages viewed by users. The issue has been patched in version 3.2.3. A fix was committed to the official GitHub repository and a security advisory was published via GitHub Security Advisories. Users are advised to upgrade to version 3.2.3 or later to mitigate the risk.