A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Combodo iTop, a web-based IT service management tool. The vulnerability exists in the dashboard save functionality and affects versions prior to 3.2.3. Reflected XSS vulnerabilities allow attackers to inject malicious scripts that are reflected off the web server to the victim's browser. The flaw could be exploited to steal session cookies, redirect users, or perform actions on behalf of authenticated users. The issue has been addressed and patched in iTop version 3.2.3. A fix has been committed to the official GitHub repository and a security advisory has been published. Users are strongly advised to upgrade to version 3.2.3 or later. The vulnerability is tracked under CVE-2026-30865 and has an associated GitHub Security Advisory GHSA-8j4q-ccr6-wpmj.