Combodo iTop, a web-based IT service management tool, was found to contain a Reflected Cross-Site Scripting (XSS) vulnerability in its foreign key search criteria API. The vulnerability affects versions prior to 3.2.3. Reflected XSS vulnerabilities allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, credential theft, or other client-side attacks. The issue has been assigned CVE-2026-33240 and was fixed in version 3.2.3. A patch commit is available on GitHub along with a security advisory. Users are advised to upgrade to iTop 3.2.3 or later to mitigate this risk.