CVE-2026-31936 affects Combodo iTop, a web-based IT service management tool. Prior to version 3.2.3, authenticated users could access unauthorized object information through the search functionality, constituting an improper access control vulnerability. This represents an information disclosure issue where users could retrieve data beyond their intended permissions. The vulnerability has been patched in iTop version 3.2.3. A fix was committed to the official GitHub repository and a security advisory was published on GitHub. No active exploitation has been mentioned, but the nature of the flaw poses a risk to organizations relying on iTop for ITSM workflows. Users are advised to upgrade to version 3.2.3 or later immediately.